PT-2020-19352 · Fortinet+2 · Openfortivpn+2
Agustingianni
·
Published
2020-02-27
·
Updated
2024-06-15
·
CVE-2020-7042
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
openfortivpn version 1.11.0
Description
An issue in openfortivpn, when used with OpenSSL 1.0.2 or later, causes the
tunnel.c component to mishandle certificate validation. This occurs because the hostname check operates on uninitialized memory, resulting in a valid certificate never being accepted, while a malformed certificate may be accepted.Recommendations
For openfortivpn version 1.11.0, consider updating to a newer version that addresses the certificate validation issue, as the current version may not properly accept valid certificates due to the mishandling of certificate validation in the
tunnel.c component.Fix
Use of Uninitialized Resource
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Suse
Openfortivpn