6.8

CVE-2008-2420

The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StunnelStunnel Version3.4a
StunnelStunnel Version3.5
StunnelStunnel Version3.6
StunnelStunnel Version3.7
StunnelStunnel Version3.8
StunnelStunnel Version3.8p1
StunnelStunnel Version3.8p2
StunnelStunnel Version3.8p3
StunnelStunnel Version3.8p4
StunnelStunnel Version3.9
StunnelStunnel Version3.10
StunnelStunnel Version3.11
StunnelStunnel Version3.12
StunnelStunnel Version3.13
StunnelStunnel Version3.14
StunnelStunnel Version3.15
StunnelStunnel Version3.16
StunnelStunnel Version3.17
StunnelStunnel Version3.18
StunnelStunnel Version3.19
StunnelStunnel Version3.20
StunnelStunnel Version3.21
StunnelStunnel Version3.21a
StunnelStunnel Version3.21b
StunnelStunnel Version3.21c
StunnelStunnel Version3.22
StunnelStunnel Version3.23
StunnelStunnel Version3.24
StunnelStunnel Version3.25
StunnelStunnel Version3.26
StunnelStunnel Version4.00
StunnelStunnel Version4.01
StunnelStunnel Version4.02
StunnelStunnel Version4.03
StunnelStunnel Version4.04
StunnelStunnel Version4.05
StunnelStunnel Version4.06
StunnelStunnel Version4.07
StunnelStunnel Version4.08
StunnelStunnel Version4.09
StunnelStunnel Version4.10
StunnelStunnel Version4.11
StunnelStunnel Version4.12
StunnelStunnel Version4.13
StunnelStunnel Version4.14
StunnelStunnel Version4.15
StunnelStunnel Version4.16
StunnelStunnel Version4.17
StunnelStunnel Version4.18
StunnelStunnel Version4.19
StunnelStunnel Version4.20
StunnelStunnel Version4.21
StunnelStunnel Version4.22
StunnelStunnel Version4.23
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.626
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P