CVE-2008-2420

Description

The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.488

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in stunnel 3.4aWindows
Multiple Vulnerabilities are affected in stunnel 3.7Windows
Multiple Vulnerabilities are affected in stunnel 3.8Windows
Multiple Vulnerabilities are affected in stunnel 3.10Windows
Multiple Vulnerabilities are affected in stunnel 3.11Windows
Multiple Vulnerabilities are affected in stunnel 3.12Windows
Multiple Vulnerabilities are affected in stunnel 3.13Windows
Multiple Vulnerabilities are affected in stunnel 3.14Windows
Multiple Vulnerabilities are affected in stunnel 3.15Windows
Multiple Vulnerabilities are affected in stunnel 3.16Windows
Multiple Vulnerabilities are affected in stunnel 3.17Windows
Multiple Vulnerabilities are affected in stunnel 3.18Windows
Multiple Vulnerabilities are affected in stunnel 3.19Windows
Multiple Vulnerabilities are affected in stunnel 3.20Windows
Multiple Vulnerabilities are affected in stunnel 3.21Windows
Multiple Vulnerabilities are affected in stunnel 3.21aWindows
Multiple Vulnerabilities are affected in stunnel 3.21bWindows
Multiple Vulnerabilities are affected in stunnel 3.21cWindows
Multiple Vulnerabilities are affected in stunnel 3.22Windows
Multiple Vulnerabilities are affected in stunnel 3.24Windows
Multiple Vulnerabilities are affected in stunnel 3.9Windows
Multiple Vulnerabilities are affected in stunnel 4.04Windows
Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.01Windows
Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.02Windows
Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.03Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.5Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.6Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.05Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.06Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.07Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.08Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.09Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.10Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.11Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.12Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.13Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.14Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.15Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.16Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.17Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.18Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.19Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.20Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.21Windows
Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.22Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.23Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.25Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.26Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p1Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p2Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p3Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p4Windows
Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.00Windows
Vulnerabilities CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.23Windows
CVE-2008-2420NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234