Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Infradead openconnect输入验证漏洞
Vulnerability Description
OpenConnect 是思科AnyConnect VPN的一个开放客户端。 OpenConnect 2.25之前的版本不能正确校验X.509证书。中间人攻击者可以借助(1)不符合服务器的主机名或者(2)提出涉及missing --cafile配置选项相关情况下特制的服务器证书欺骗任意AnyConnect SSL VPN服务器。
CVSS Information
N/A
Vulnerability Type
N/A