ID

VAR-201010-0435


CVE

CVE-2010-3903


TITLE

OpenConnect Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2010-003269

DESCRIPTION

Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a 404 HTTP status code. Openconnect is prone to a denial-of-service vulnerability. OpenConnect is an open client for Cisco AnyConnect VPN. An unspecified vulnerability exists in versions prior to OpenConnect 2.23

Trust: 1.98

sources: NVD: CVE-2010-3903 // JVNDB: JVNDB-2010-003269 // BID: 78757 // VULHUB: VHN-46508

AFFECTED PRODUCTS

vendor:infradeadmodel:openconnectscope:eqversion:2.20

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:2.11

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:2.10

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:2.01

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:2.00

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:1.40

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:1.30

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:1.20

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:1.10

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:1.00

Trust: 1.9

vendor:infradeadmodel:openconnectscope:eqversion:2.21

Trust: 1.3

vendor:infradeadmodel:openconnectscope:eqversion:2.12

Trust: 1.3

vendor:infradeadmodel:openconnectscope:lteversion:2.22

Trust: 1.0

vendor:infradeadmodel:openconnectscope:ltversion:2.23

Trust: 0.8

vendor:infradeadmodel:openconnectscope:eqversion:2.22

Trust: 0.3

sources: BID: 78757 // JVNDB: JVNDB-2010-003269 // CNNVD: CNNVD-201010-216 // NVD: CVE-2010-3903

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-3903
value: MEDIUM

Trust: 1.0

NVD: CVE-2010-3903
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201010-216
value: MEDIUM

Trust: 0.6

VULHUB: VHN-46508
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2010-3903
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-46508
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-46508 // JVNDB: JVNDB-2010-003269 // CNNVD: CNNVD-201010-216 // NVD: CVE-2010-3903

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2010-3903

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201010-216

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201010-216

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-003269

PATCH

title:OpenConnecturl:http://www.infradead.org/openconnect.html

Trust: 0.8

title:openconnect-2.23url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=23709

Trust: 0.6

title:openconnect-2.23url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=23708

Trust: 0.6

sources: JVNDB: JVNDB-2010-003269 // CNNVD: CNNVD-201010-216

EXTERNAL IDS

db:NVDid:CVE-2010-3903

Trust: 2.8

db:JVNDBid:JVNDB-2010-003269

Trust: 0.8

db:CNNVDid:CNNVD-201010-216

Trust: 0.7

db:BIDid:78757

Trust: 0.4

db:VULHUBid:VHN-46508

Trust: 0.1

sources: VULHUB: VHN-46508 // BID: 78757 // JVNDB: JVNDB-2010-003269 // CNNVD: CNNVD-201010-216 // NVD: CVE-2010-3903

REFERENCES

url:http://www.infradead.org/openconnect.html

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-3903

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-3903

Trust: 0.8

sources: VULHUB: VHN-46508 // BID: 78757 // JVNDB: JVNDB-2010-003269 // CNNVD: CNNVD-201010-216 // NVD: CVE-2010-3903

CREDITS

Unknown

Trust: 0.3

sources: BID: 78757

SOURCES

db:VULHUBid:VHN-46508
db:BIDid:78757
db:JVNDBid:JVNDB-2010-003269
db:CNNVDid:CNNVD-201010-216
db:NVDid:CVE-2010-3903

LAST UPDATE DATE

2025-04-11T23:20:45.189000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-46508date:2010-11-12T00:00:00
db:BIDid:78757date:2010-10-14T00:00:00
db:JVNDBid:JVNDB-2010-003269date:2012-03-27T00:00:00
db:CNNVDid:CNNVD-201010-216date:2010-10-18T00:00:00
db:NVDid:CVE-2010-3903date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-46508date:2010-10-14T00:00:00
db:BIDid:78757date:2010-10-14T00:00:00
db:JVNDBid:JVNDB-2010-003269date:2012-03-27T00:00:00
db:CNNVDid:CNNVD-201010-216date:2010-10-18T00:00:00
db:NVDid:CVE-2010-3903date:2010-10-14T05:58:42.957