cbcvebase.
CVE-2010-3903
published 2010-10-14

CVE-2010-3903: Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a 404 HTTP…

PriorityP414medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
0.98%
58.3th percentile
Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a 404 HTTP status code.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianopenconnect< openconnect 2.25-0.1 (bookworm)openconnect 2.25-0.1 (bookworm)
infradeadopenconnect<= 2.22
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect
infradeadopenconnect>= 0 < 2.25-0.12.25-0.1
infradeadopenconnect>= 0 < 2.25-0.12.25-0.1
infradeadopenconnect>= 0 < 2.25-0.12.25-0.1
infradeadopenconnect>= 0 < 2.25-0.12.25-0.1

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.