VYPR

openfortivpn

by adrienverge

CVEs (2)

  • CVE-2020-7043Feb 27, 2020
    risk 0.00cvss epss 0.00

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

  • CVE-2020-7042Feb 27, 2020
    risk 0.00cvss epss 0.01

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate…