OpenSSL CVE-2020-7041 Certificate Validation Bypass Vulnerability

description-logoDescription

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.

affected-products-logoAffected Applications

OpenSSL

CVE References

CVE-2020-7041