CVE-2010-3902: Infoleak
OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output posted to the public openconnect-devel mailing list.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3902?
CVE-2010-3902 has been classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2010-3902?
To remediate CVE-2010-3902, update OpenConnect to version 2.26 or later.
What software is affected by CVE-2010-3902?
CVE-2010-3902 affects OpenConnect versions prior to 2.26, including versions 1.00, 1.10, 1.20, 1.30, and 2.22.
What type of vulnerability is CVE-2010-3902?
CVE-2010-3902 is a vulnerability that allows for the leakage of sensitive information through debugging output.
What can attackers do with CVE-2010-3902?
Attackers exploiting CVE-2010-3902 can read sensitive cookie values from debugging outputs, potentially compromising user sessions.