CVE-2020-7043
published 2020-02-27CVE-2020-7043: An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do…
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
2.46%
82.7th percentile
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openfortivpn | < openfortivpn 1.12.0-1 (bookworm) | openfortivpn 1.12.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openfortivpn_project | openfortivpn | < 1.12.0 | 1.12.0 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| openfortivpn_project | openfortivpn | >= 0 < 1.12.0-1 | 1.12.0-1 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pqj-5gg5-44jh: An issue was discovered in openfortivpn 1
ghsa_unreviewed·2022-05-24
CVE-2020-7043 [CRITICAL] CWE-295 GHSA-4pqj-5gg5-44jh: An issue was discovered in openfortivpn 1
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
OSV
CVE-2020-7043: An issue was discovered in openfortivpn 1
osv·2020-02-27·CVSS 9.1
CVE-2020-7043 [CRITICAL] CVE-2020-7043: An issue was discovered in openfortivpn 1
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
Debian
CVE-2020-7043: openfortivpn - An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0...
vendor_debian·2020·CVSS 9.1
CVE-2020-7043 [CRITICAL] CVE-2020-7043: openfortivpn - An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0...
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
Scope: local
bookworm: resolved (fixed in 1.12.0-1)
bullseye: resolved (fixed in 1.12.0-1)
forky: resolved (fixed in 1.12.0-1)
sid: resolved (fixed in 1.12.0-1)
trixie: resolved (fixed in 1.12.0-1)
No detection rules found.
No public exploits indexed.
Unit42
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
blogs_unit42·2021-08-17
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
## Executive Summary
Organizations are facing an increase in obfuscation behavior from on-site and remote employees attempting to bypass proxy servers to hide their online activities or exfiltrate data without detection. For example, an employee might use the “incognito” mode, download a personal virtual private network (VPN) or the Tor browser, or bypass the corporate VPN. In those cases, the information security team (InfoSec) needs complete network visibility to determine if that employee is solely guarding their own privacy, masking behavior that breaks organization policies or attempting to cover an attack.
Personal VPN services promise to enable secure, encrypted tunnels for user traffic. They provide services that prevent others from seeing through these tunnels by encrypting the
Unit42
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
blogs_unit42·2021-08-17
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
Threat Research Center
Threat Research
Cybercrime
## Personal VPN and Its Evasions: Risk Factors and How to Maintain Network Visibility
Saeed Abbasi
Kirti Parekh
Published: August 16, 2021
Cybercrime
Threat Research
Data exfiltration
Insider threats
VPN
## Executive Summary
Organizations are facing an increase in obfuscation behavior from on-site and remote employees attempting to bypass proxy servers to hide their online activities or exfiltrate data without detection. For example, an employee might use the “incognito” mode, download a personal virtual private network (VPN) or the Tor browser, or bypass the corporate VPN. In those cases, the information security team (InfoSec) needs complete network visibility to determine if that employee is solely guarding their own pri
Bugzilla
CVE-2020-7043 openfortivpn: mishandling of certificate validation
bugzilla·2020-05-05·CVSS 9.1
CVE-2020-7043 [CRITICAL] CVE-2020-7043 openfortivpn: mishandling of certificate validation
CVE-2020-7043 openfortivpn: mishandling of certificate validation
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
References:
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.html
https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4
https://github.com/adrienverge/openfortivpn/issues/536
https://lists.fedoraproject.org/archives/list/[email protected]/message/FF6HYIBREQGATRM5COF57MRQWKOKCWZ3/
https://lists.fedoraproject.org/archive
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlhttps://github.com/adrienverge/openfortivpn/commit/6328a070ddaab16faaf008cb9a8a62439c30f2a8https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4https://github.com/adrienverge/openfortivpn/issues/536https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKNKSGBVYGRRVRLFEFBEKUEJYJR5LWOF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FF6HYIBREQGATRM5COF57MRQWKOKCWZ3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SRVVNXCNTNMPCIAZIVR4FAGYCSU53FNA/http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlhttps://github.com/adrienverge/openfortivpn/commit/6328a070ddaab16faaf008cb9a8a62439c30f2a8https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4https://github.com/adrienverge/openfortivpn/issues/536https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKNKSGBVYGRRVRLFEFBEKUEJYJR5LWOF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FF6HYIBREQGATRM5COF57MRQWKOKCWZ3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SRVVNXCNTNMPCIAZIVR4FAGYCSU53FNA/
2020-02-27
Published