Lucene search

K
cvelistOpenVPNCVELIST:CVE-2020-15078
HistoryApr 26, 2021 - 1:19 p.m.

CVE-2020-15078

2021-04-2613:19:45
CWE-305
OpenVPN
www.cve.org
5
openvpn 2.5.1
remote attackers
authentication bypass
access control
information leaks

AI Score

7.6

Confidence

High

EPSS

0.029

Percentile

90.8%

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CNA Affected

[
  {
    "product": "OpenVPN",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "2.5.1 and earlier versions"
      }
    ]
  }
]