cbcvebase.
CVE-2020-15078
published 2021-04-26

CVE-2020-15078: OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred…

PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
5.11%
91.4th percentile
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianopenvpn< openvpn 2.5.1-2 (bookworm)openvpn 2.5.1-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
openvpnopenvpn< 2.4.112.4.11
openvpnopenvpn
openvpnopenvpn>= 0 < 2.5.1-22.5.1-2
openvpnopenvpn>= 0 < 2.5.1-22.5.1-2
openvpnopenvpn>= 0 < 2.5.1-22.5.1-2
openvpnopenvpn>= 0 < 2.5.1-22.5.1-2
openvpnopenvpn>= 0 < 2.4.4-2ubuntu1.52.4.4-2ubuntu1.5
openvpnopenvpn>= 0 < 2.4.7-1ubuntu2.20.04.22.4.7-1ubuntu2.20.04.2
openvpnopenvpn>= 2.5.0 < 2.5.22.5.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.