CVE-2020-7043

CRITICAL

Openfortivpn < 1.12.0 - Improper Certificate Validation

Title source: rule
STIX 2.1

Description

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

Scores

CVSS v3 9.1
EPSS 0.0047
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (6)
fedoraproject/fedora 30
fedoraproject/fedora 31
fedoraproject/fedora 32
openfortivpn_project/openfortivpn < 1.12.0
opensuse/backports_sle 15.0 sp1
opensuse/leap 15.1
Published Feb 27, 2020
Tracked Since Feb 18, 2026