Description
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2992-1 | openvpn security update |
Debian DLA |
DLA-4079-1 | openvpn security update |
EUVD |
EUVD-2022-15669 | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials. |
Ubuntu USN |
USN-5347-1 | OpenVPN vulnerability |
Ubuntu USN |
USN-6850-1 | OpenVPN vulnerability |
References
History
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2025-11-03T20:34:30.191Z
Reserved: 2022-02-08T00:00:00.000Z
Link: CVE-2022-0547
Updated: 2025-11-03T20:34:30.191Z
Status : Modified
Published: 2022-03-18T18:15:12.017
Modified: 2025-11-03T21:15:49.843
Link: CVE-2022-0547
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN