PT-2020-19352 · Fortinet+2 · Openfortivpn+2

Agustingianni

·

Published

2020-02-27

·

Updated

2024-06-15

·

CVE-2020-7042

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions openfortivpn version 1.11.0
Description An issue in openfortivpn, when used with OpenSSL 1.0.2 or later, causes the tunnel.c component to mishandle certificate validation. This occurs because the hostname check operates on uninitialized memory, resulting in a valid certificate never being accepted, while a malformed certificate may be accepted.
Recommendations For openfortivpn version 1.11.0, consider updating to a newer version that addresses the certificate validation issue, as the current version may not properly accept valid certificates due to the mishandling of certificate validation in the tunnel.c component.

Fix

Use of Uninitialized Resource

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7042
OPENSUSE-SU-2020:0301-1
OPENSUSE-SU-2020:0305-1
OPENSUSE-SU-2020_0301-1
OPENSUSE-SU-2024:11118-1

Affected Products

Openssl
Suse
Openfortivpn