← Back

CVE-2010-3901

nvd nist
Published: Oct 14, 2010Modified: Apr 29, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

Affected (5)

1 product
Openconnect
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Infradead
Up to 2.22
Version 1.00
Version 1.10
Version 1.20
Version 1.30

References (6)

Timeline

No history available yet.