Impact
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS will ignore the configured X.509 username identity lookup field, causing remote authenticated users to be misidentified as other users. This identity confusion allows a malicious client to impersonate another user without possessing that user’s credentials, potentially gaining unauthorized access to restricted services. The vulnerability is a form of authentication bypass rather than a denial‑of‑service or code‑execution flaw.
Affected Systems
The affected system is OpenVPN by OpenVPN, specifically releases 2.7_alpha1 through 2.7.5 that use mbedTLS. No other products or vendors are listed. The issue directly impacts configurations that rely on X.509 certificates for user identity lookup.
Risk and Exploitability
The CVSS score of 2 indicates a low severity assessment. EPSS is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of exploitation. The attack vector, as described, appears to be remote and requires an authenticated client that can present a certificate. The flaw involves ignoring a configuration field, so exploitation would require the attacker to have a valid client certificate and network access to the OpenVPN server.
OpenCVE Enrichment