CVE-2015-3644: Stunnel
Medium severity, CVSS 5.8. EPSS: 2.1% chance of exploitation in the next 30 days.
Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.
Affected products
- Stunnel Stunnel: version 5.00 only; version 5.01 only; version 5.02 only; version 5.03 only; version 5.04 only; version 5.05 only; …
Published 2015-05-14. Last modified 2026-06-17.