CVE-2010-3901
published 2010-10-14CVE-2010-3901: OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers…
PriorityP428medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
0.61%
45.6th percentile
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openconnect | < openconnect 2.25-0.1 (bookworm) | openconnect 2.25-0.1 (bookworm) |
| infradead | openconnect | <= 2.22 | — |
| infradead | openconnect | — | — |
| infradead | openconnect | — | — |
| infradead | openconnect | — | — |
| infradead | openconnect | — | — |
| infradead | openconnect | >= 0 < 2.25-0.1 | 2.25-0.1 |
| infradead | openconnect | >= 0 < 2.25-0.1 | 2.25-0.1 |
| infradead | openconnect | >= 0 < 2.25-0.1 | 2.25-0.1 |
| infradead | openconnect | >= 0 < 2.25-0.1 | 2.25-0.1 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92px-2chv-hqhf: OpenConnect before 2
ghsa_unreviewed·2022-05-17
CVE-2010-3901 [MEDIUM] CWE-20 GHSA-92px-2chv-hqhf: OpenConnect before 2
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.
OSV
CVE-2010-3901: OpenConnect before 2
osv·2010-10-14·CVSS 6.4
CVE-2010-3901 [MEDIUM] CVE-2010-3901: OpenConnect before 2
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.
Debian
CVE-2010-3901: openconnect - OpenConnect before 2.25 does not properly validate X.509 certificates, which all...
vendor_debian·2010·CVSS 6.4
CVE-2010-3901 [MEDIUM] CVE-2010-3901: openconnect - OpenConnect before 2.25 does not properly validate X.509 certificates, which all...
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.
Scope: local
bookworm: resolved (fixed in 2.25-0.1)
bullseye: resolved (fixed in 2.25-0.1)
forky: resolved (fixed in 2.25-0.1)
sid: resolved (fixed in 2.25-0.1)
trixie: resolved (fixed in 2.25-0.1)
No detection rules found.
Bugzilla
CVE-2010-3902 OpenConnect: webvpn cookie content disclosure via debugging output
bugzilla·2010-10-15·CVSS 6.4
CVE-2010-3902 [MEDIUM] CVE-2010-3902 OpenConnect: webvpn cookie content disclosure via debugging output
CVE-2010-3902 OpenConnect: webvpn cookie content disclosure via debugging output
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-3902 to
the following vulnerability:
OpenConnect before 2.26 places the webvpn cookie value in the
debugging output, which might allow remote attackers to obtain
sensitive information by reading this output, as demonstrated by
output posted to the public openconnect-devel mailing list.
References:
[1] http://www.infradead.org/openconnect.html
Upstream changeset:
[2] http://git.infradead.org/users/dwmw2/openconnect.git/commit/673c83fbb439090f16779dfdcd6a4e6026f16ac6
Vulnerable Fedora openconnect versions:
This issue affects the version of the openconnect package, as shipped
with Fedora release of 12.
Please fix (schedule F-12 openconnect
Bugzilla
CVE-2010-3901 OpenConnect: Always validate server certificate, check server hostname against its certificate
bugzilla·2010-08-01·CVSS 6.4
CVE-2010-3901 [MEDIUM] CVE-2010-3901 OpenConnect: Always validate server certificate, check server hostname against its certificate
CVE-2010-3901 OpenConnect: Always validate server certificate, check server hostname against its certificate
OpenConnect upstream has released OpenConnect v2.25:
[1] http://www.infradead.org/openconnect.html
addressing following security related issues (from [1]):
OpenConnect v2.25 — 2010-05-15
* Always validate server certificate, even when no extra --cafile
is provided.
* Add --no-cert-check option to avoid certificate validation.
* Check server hostname against its certificate.
* Provide text-mode function for reviewing and accepting "invalid"
certificates.
* Fix libproxy detection on NetBSD.
References:
[2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590873
[3] ftp://ftp.infradead.org/pub/openconnect/openconnect-2.25.tar.gz
Discussion:
This issues affect the versions of the
Bugzilla
OpenConnect: Always validate server certificate, check server hostname against its certificate [fedora-all]
bugzilla·2010-08-01
[LOW] OpenConnect: Always validate server certificate, check server hostname against its certificate [fedora-all]
OpenConnect: Always validate server certificate, check server hostname against its certificate [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=620219
Please
http://www.infradead.org/openconnect.htmlhttp://www.openwall.com/lists/oss-security/2010/08/01/1http://www.openwall.com/lists/oss-security/2010/08/02/7http://www.infradead.org/openconnect.htmlhttp://www.openwall.com/lists/oss-security/2010/08/01/1http://www.openwall.com/lists/oss-security/2010/08/02/7
2010-10-14
Published