QID 355075

Date Published: 2023-05-18

QID 355075: Amazon Linux Security Advisory for Open Virtual Private Network (OpenVPN) : AL2012-2023-399

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-0547:
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 355075

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2023-399 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html