CVE-2020-7042
published 2020-02-27CVE-2020-7042: An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.58%
72.9th percentile
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openfortivpn | < openfortivpn 1.12.0-1 (bookworm) | openfortivpn 1.12.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openfortivpn_project | openfortivpn | < 1.12.0 | 1.12.0 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8w9v-97h7-m2j5: An issue was discovered in openfortivpn 1
ghsa_unreviewed·2022-05-24
CVE-2020-7042 [MEDIUM] CWE-295 GHSA-8w9v-97h7-m2j5: An issue was discovered in openfortivpn 1
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
OSV
CVE-2020-7042: An issue was discovered in openfortivpn 1
osv·2020-02-27·CVSS 5.3
CVE-2020-7042 [MEDIUM] CVE-2020-7042: An issue was discovered in openfortivpn 1
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
Debian
CVE-2020-7042: openfortivpn - An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or l...
vendor_debian·2020·CVSS 5.3
CVE-2020-7042 [MEDIUM] CVE-2020-7042: openfortivpn - An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or l...
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
Scope: local
bookworm: resolved (fixed in 1.12.0-1)
bullseye: resolved (fixed in 1.12.0-1)
forky: resolved (fixed in 1.12.0-1)
sid: resolved (fixed in 1.12.0-1)
trixie: resolved (fixed in 1.12.0-1)
No detection rules found.
No public exploits indexed.
Unit42
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
blogs_unit42·2021-08-17
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
## Executive Summary
Organizations are facing an increase in obfuscation behavior from on-site and remote employees attempting to bypass proxy servers to hide their online activities or exfiltrate data without detection. For example, an employee might use the “incognito” mode, download a personal virtual private network (VPN) or the Tor browser, or bypass the corporate VPN. In those cases, the information security team (InfoSec) needs complete network visibility to determine if that employee is solely guarding their own privacy, masking behavior that breaks organization policies or attempting to cover an attack.
Personal VPN services promise to enable secure, encrypted tunnels for user traffic. They provide services that prevent others from seeing through these tunnels by encrypting the
Unit42
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
blogs_unit42·2021-08-17
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
Threat Research Center
Threat Research
Cybercrime
## Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
Saeed Abbasi
Kirti Parekh
Published: August 16, 2021
Cybercrime
Threat Research
Data exfiltration
Insider threats
VPN
## Executive Summary
Organizations are facing an increase in obfuscation behavior from on-site and remote employees attempting to bypass proxy servers to hide their online activities or exfiltrate data without detection. For example, an employee might use the “incognito” mode, download a personal virtual private network (VPN) or the Tor browser, or bypass the corporate VPN. In those cases, the information security team (InfoSec) needs complete network visibility to determine if that employee is solely guarding their own pri
Bugzilla
CVE-2020-7042 openfortivpn: mishandling of certificate validation due to an uninitialized memory
bugzilla·2020-05-05·CVSS 5.3
CVE-2020-7042 [MEDIUM] CVE-2020-7042 openfortivpn: mishandling of certificate validation due to an uninitialized memory
CVE-2020-7042 openfortivpn: mishandling of certificate validation due to an uninitialized memory
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
References:
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.html
https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4
https://github.com/adrienverge/openfortivpn/issues/536
https://lists.fedoraproject.org/archives/list/[email protected]/message/F
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlhttps://github.com/adrienverge/openfortivpn/commit/9eee997d599a89492281fc7ffdd79d88cd61afc3https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4https://github.com/adrienverge/openfortivpn/issues/536https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKNKSGBVYGRRVRLFEFBEKUEJYJR5LWOF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FF6HYIBREQGATRM5COF57MRQWKOKCWZ3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SRVVNXCNTNMPCIAZIVR4FAGYCSU53FNA/http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlhttps://github.com/adrienverge/openfortivpn/commit/9eee997d599a89492281fc7ffdd79d88cd61afc3https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4https://github.com/adrienverge/openfortivpn/issues/536https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKNKSGBVYGRRVRLFEFBEKUEJYJR5LWOF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FF6HYIBREQGATRM5COF57MRQWKOKCWZ3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SRVVNXCNTNMPCIAZIVR4FAGYCSU53FNA/
2020-02-27
Published