Impact
A malformed authentication token can trigger a reachable assertion in OpenVPN when the external-auth feature is enabled, causing the server process to crash. The crash terminates all VPN tunnel sessions, resulting in a loss of connectivity for all connected clients until the service restarts. The weakness corresponds to CWE‑617, reflecting improper input validation that leads to application failure.
Affected Systems
OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 are susceptible to this flaw. The vulnerability activates only when the external-auth option is enabled in the server configuration.
Risk and Exploitability
The CVSS score of 5.9 denotes moderate severity, and the EPSS score of less than 1 percent indicates a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. An attacker capable of forging a token can remotely exploit the flaw without requiring local privileges; exploitation requires that the external-auth facility be active on the target server.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN