QID 375518

Date Published: 2021-05-06

QID 375518: OpenVpn 2.5.1 and earlier Authentication Bypass (excluding 2.4.11)

OpenVPN is an OpenSSL based tunneling application to securely tunnel IP networks over the TCP and UDP protocols.

Vulnerability allows a remote attackers to bypass authentication.

Affected Versions:
OpenVPN 2.5.1 and earlier (except 2.4.11)

Successful exploitation of this vulnerability allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Users are advised to upgrade to the latest version of the software available. Latest version of the software can be downloaded from OpenVPN

    CVEs related to QID 375518

    Software Advisories
    Advisory ID Software Component Link
    OpenVpn Windows URL Logo openvpn.net/community-downloads/