// For flags

CVE-2015-3644

Debian Security Advisory 3299-1

Severity Score

10.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.

Stunnel 5.00 hasta 5.13, cuando utiliza la opción de redirección, no redirige las conexiones de clientes al servidor esperado después de la conexión inicial, lo que permite a atacantes remotos evadir la autenticación.

Johan Olofsson discovered an authentication bypass vulnerability in Stunnel, a program designed to work as an universal SSL tunnel for network daemons. When Stunnel in server mode is used with the redirect option and certificate-based authentication is enabled with "verify = 2" or higher, then only the initial connection is redirected to the hosts specified with "redirect". This allows a remote attacker to bypass authentication.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-05-04 CVE Reserved
  • 2015-05-14 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.00
Search vendor "Stunnel" for product "Stunnel" and version "5.00"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.01
Search vendor "Stunnel" for product "Stunnel" and version "5.01"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.02
Search vendor "Stunnel" for product "Stunnel" and version "5.02"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.03
Search vendor "Stunnel" for product "Stunnel" and version "5.03"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.04
Search vendor "Stunnel" for product "Stunnel" and version "5.04"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.05
Search vendor "Stunnel" for product "Stunnel" and version "5.05"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.06
Search vendor "Stunnel" for product "Stunnel" and version "5.06"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.07
Search vendor "Stunnel" for product "Stunnel" and version "5.07"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.08
Search vendor "Stunnel" for product "Stunnel" and version "5.08"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.09
Search vendor "Stunnel" for product "Stunnel" and version "5.09"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.10
Search vendor "Stunnel" for product "Stunnel" and version "5.10"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.11
Search vendor "Stunnel" for product "Stunnel" and version "5.11"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.12
Search vendor "Stunnel" for product "Stunnel" and version "5.12"
-
Affected
Stunnel
Search vendor "Stunnel"
Stunnel
Search vendor "Stunnel" for product "Stunnel"
5.13
Search vendor "Stunnel" for product "Stunnel" and version "5.13"
-
Affected