Ok. Thanks for your answer. Regards Aamir Ahmed -----Original Message----- From: David Woodhouse [mailto:dwmw2 at infradead.org] Sent: Monday, October 27, 2014 2:24 PM To: Aamir Ahmed -X (amiahmed) Cc: openconnect-devel at lists.infradead.org; email-in(mailer list); Himanshu Sharma -X (himanssh) Subject: Re: SR: 632254965 On Tue, 2014-10-21 at 13:42 +0000, Aamir Ahmed -X (amiahmed) wrote: > Your understanding is correct David. Is there any NIST CVEs that was > filled to track this? No. It's not really something that's worthy of a CVE. It's just a fundamental design flaw in the whole approach. -- dwmw2 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 6049 bytes Desc: not available URL: <http://lists.infradead.org/pipermail/openconnect-devel/attachments/20141027/92753c55/attachment-0001.p7s>