QID 375518
Date Published: 2021-05-06
QID 375518: OpenVpn 2.5.1 and earlier Authentication Bypass (excluding 2.4.11)
OpenVPN is an OpenSSL based tunneling application to securely tunnel IP networks over the TCP and UDP protocols.
Vulnerability allows a remote attackers to bypass authentication.
Affected Versions:
OpenVPN 2.5.1 and earlier (except 2.4.11)
Successful exploitation of this vulnerability allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Solution
Users are advised to upgrade to the latest version of the software available. Latest version of the software can be downloaded from OpenVPN
Vendor References
CVEs related to QID 375518
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenVpn | Windows |
|