OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 12, 2020 |
| Debian | — | Upgrade openconnect | May 19, 2020 | May 12, 2020 |
| Gentoo Linux | — | Upgrade net-vpn/openconnect. | Jun 16, 2020 | May 12, 2020 |
| Suse | — | Upgrade openconnect-langUpgrade openconnectUpgrade openconnect-docUpgrade openconnect-devel | Jul 19, 2020 | May 12, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub