VYPR
Unrated severityNVD Advisory· Published May 14, 2015· Updated May 6, 2026

CVE-2015-3644

CVE-2015-3644

Description

Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.

Affected products

14
  • Stunnel/Stunnel14 versions
    cpe:2.3:a:stunnel:stunnel:5.02:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:stunnel:stunnel:5.02:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.03:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.04:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.05:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.06:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.07:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.08:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.09:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.11:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.12:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.13:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.00:*:*:*:*:*:*:*
    • cpe:2.3:a:stunnel:stunnel:5.01:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.