OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2992-1 openvpn security update
EUVD EUVD EUVD-2020-7206 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Ubuntu USN Ubuntu USN USN-4933-1 OpenVPN vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2024-08-04T13:08:21.675Z

Reserved: 2020-06-25T00:00:00

Link: CVE-2020-15078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-26T14:15:08.623

Modified: 2024-11-21T05:04:45.900

Link: CVE-2020-15078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.