OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openvpn | Mar 26, 2024 | Apr 26, 2021 |
| Amazon_linux | — | Upgrade openvpn | Sep 9, 2021 | Apr 26, 2021 |
| Debian | — | Upgrade openvpn | May 5, 2022 | Apr 26, 2021 |
| Freebsd | — | Upgrade openvpnUpgrade openvpn-mbedtls | Nov 4, 2022 | Apr 21, 2021 |
| Gentoo Linux | — | Upgrade net-vpn/openvpn. | May 28, 2021 | Apr 26, 2021 |
| Suse | — | Upgrade openvpn-openssl1-down-root-pluginUpgrade openvpn-openssl1Upgrade openvpn-down-root-pluginUpgrade openvpn-auth-pam-pluginUpgrade openvpn-develUpgrade openvpn | May 13, 2021 | Apr 26, 2021 |
| Ubuntu | — | Upgrade openvpn | May 5, 2021 | Apr 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub