CVE-2010-3902Sensitive Information Exposure in Openconnect

Severity
5.0MEDIUMNVD
EPSS
0.6%
top 31.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 14
Latest updateMay 17

Description

OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output posted to the public openconnect-devel mailing list.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianinfradead/openconnect< 3.02-1+3

🔴Vulnerability Details

3
GHSA
GHSA-mvq9-gwc4-9r68: OpenConnect before 22022-05-17
OSV
CVE-2010-3902: OpenConnect before 22010-10-14
CVEList
CVE-2010-3902: OpenConnect before 22010-10-12

📋Vendor Advisories

1
Debian
CVE-2010-3902: openconnect - OpenConnect before 2.26 places the webvpn cookie value in the debugging output, ...2010

💬Community

1
Bugzilla
CVE-2010-3902 OpenConnect: webvpn cookie content disclosure via debugging output2010-10-15
CVE-2010-3902 — Sensitive Information Exposure | cvebase