PT-2010-5155 · Openconnect · Openconnect
Jan Lieskovsky
·
Published
2010-10-12
·
Updated
2010-10-14
·
CVE-2010-3901
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenConnect versions prior to 2.25
Description
The issue allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers by presenting a crafted server certificate. This can happen in two scenarios: (1) when the certificate does not correspond to the server hostname, or (2) when the --cafile configuration option is missing.
Recommendations
For versions prior to 2.25, update to version 2.25 or later to resolve the issue. As a temporary workaround, consider configuring the --cafile option to specify a trusted certificate authority file, and ensure that server certificates are properly validated against the server hostname.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openconnect