CVE-2020-12105

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2020
Last modified:
03/05/2022

Description

OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:infradead:openconnect:*:*:*:*:*:*:*:* 8.08 (including)
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*