MEDIUM · 5.0

CVE-2010-3902

OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output pos...

Vulnerability Description

OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output posted to the public openconnect-devel mailing list.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
InfradeadOpenconnect<= 2.25

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3902?

CVE-2010-3902 is a vulnerability with a CVSS score of 5.0 (MEDIUM). OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output pos...

How severe is CVE-2010-3902?

CVE-2010-3902 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3902?

Check the references section above for vendor advisories and patch information. Affected products include: Infradead Openconnect.