Lucene search

K
osvGoogleOSV:CVE-2022-0547
HistoryMar 18, 2022 - 6:15 p.m.

CVE-2022-0547

2022-03-1818:15:12
Google
osv.dev
12
openvpn
authentication bypass
external plug-ins
deferred authentication
access granted

AI Score

6.9

Confidence

Low

EPSS

0.008

Percentile

81.4%

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.