Impact
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line‑feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy. This flaw falls under HTTP request smuggling and request manipulation weaknesses.
Affected Systems
All OpenVPN Access Server installations from version 2.7.2 up to and including 3.1.0 are affected. Any deployment that has not been upgraded beyond 3.1.0 faces the same risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk. The EPSS score of <1% suggests a very low but nonzero likelihood of exploitation. This vulnerability is not listed in CISA’s KEV catalog. It arises when a client sends header values containing raw line‑feed characters to an Access Server behind a reverse proxy, enabling HTTP request smuggling. The attack vector is remote, requiring the ability to craft and send HTTP requests to the server.
OpenCVE Enrichment