ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-7043
+2 in the same advisory: …7041 …7042
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2.

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

NVD description · AI analysis pending
9.1
group max
3%
  • openfortivpn project openfortivpn
  • openfortivpn project fedora
  • openfortivpn project backports sle
  • +1 more