CVE-2020-7042
Last modified
CVE-2020-7042 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. EPSS estimates a 1.54% chance of exploitation in the next 30 days.
Description
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openfortivpn Project | Openfortivpn | < 1.12.0 | — |
| Fedoraproject | Fedora | 30 | — |
| Fedoraproject | Fedora | 31 | — |
| Fedoraproject | Fedora | 32 | — |
| Opensuse | Backports Sle | 15.0 | Sp1 |
| Opensuse | Leap | 15.1 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlMailing List, Third Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/9eee997d599a89492281fc7ffdd79d88cd61afc3Patch, Third Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4Patch, Third Party Advisory
- https://github.com/adrienverge/openfortivpn/issues/536Issue Tracking, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlMailing List, Third Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/9eee997d599a89492281fc7ffdd79d88cd61afc3Patch, Third Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5bc34aa6f4c4Patch, Third Party Advisory
- https://github.com/adrienverge/openfortivpn/issues/536Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7042?
How severe is CVE-2020-7042?
How do I fix CVE-2020-7042?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7036An XML External Entities (XXE)vulnerability in Callback Assi…6.5
- CVE-2020-7037An XML External Entities (XXE) vulnerability in Media Server…8.1
- CVE-2020-7038A vulnerability was discovered in Management component of Av…7.5
- CVE-2020-7039tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2…5.6
- CVE-2020-7040storeBackup.pl in storeBackup through 3.5 relies on the /tmp…8.1
- CVE-2020-7041An issue was discovered in openfortivpn 1.11.0 when used wit…5.3
- CVE-2020-7043An issue was discovered in openfortivpn 1.11.0 when used wit…9.1
- CVE-2020-7044In Wireshark 3.2.x before 3.2.1, the WASSP dissector could c…7.5
- CVE-2020-7045In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could …6.5
- CVE-2020-7046lib-smtp in submission-login and lmtp in Dovecot 2.3.9 befor…7.5
- CVE-2020-7047The WordPress plugin, WP Database Reset through 3.1, contain…8.8
- CVE-2020-7048The WordPress plugin, WP Database Reset through 3.1, contain…9.1
Are you affected by CVE-2020-7042?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
