Openfortivpn Project maintains a specialized VPN client tool that provides open-source access to Fortinet VPN appliances, serving a focused user base with a narrowly scoped vulnerability footprint. The recurring exposure centers on cryptographic validation and resource initialization within the client, specifically improper certificate validation and use of uninitialized resources that could affect secure tunnel establishment. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openfortivpn Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7043CRITICAL An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' cha | Feb 27, 2020 | 9.1 | 28 | NO | NO |
CVE-2020-7042MEDIUM An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialize | Feb 27, 2020 | 5.3 | 20 | NO | NO |
CVE-2020-7041MEDIUM An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is i | Feb 27, 2020 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openfortivpn Project.
Media articles that mention a CVE ID that affects a product developed by Openfortivpn Project — matched by CVE ID, not by vendor name.