PT-2020-19351 · Fortinet+2 · Openfortivpn+2
Agustingianni
·
Published
2020-02-27
·
Updated
2024-06-15
·
CVE-2020-7041
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
openfortivpn version 1.11.0
Description
An issue was discovered in openfortivpn when used with OpenSSL 1.0.2 or later, where the
tunnel.c file mishandles certificate validation. This occurs because a negative error code from X509 check host is incorrectly interpreted as a successful return value.Recommendations
For openfortivpn version 1.11.0, consider updating to a newer version that correctly handles certificate validation, or as a temporary workaround, restrict the use of OpenSSL to versions prior to 1.0.2 until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl
Suse
Openfortivpn