CVE-2022-0547Authentication Bypass by Primary Weakness in Openvpn

Severity
9.8CRITICALNVD
EPSS
0.6%
top 31.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateJun 26

Description

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/openvpn< openvpn 2.5.6-1 (bookworm)
NVDopenvpn/openvpn2.1.02.4.12+1
Debianopenvpn/openvpn< 2.5.1-3+deb11u1+3
CVEListV5openvpn/openvpnversion 2.1 until version 2.4.12 and 2.5.6.

Also affects: Debian Linux 9.0, Fedora 34, 36

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g28r-w65r-h89m: OpenVPN 22022-03-19
CVEList
CVE-2022-0547: OpenVPN 22022-03-18
OSV
CVE-2022-0547: OpenVPN 22022-03-18

📋Vendor Advisories

4
Ubuntu
OpenVPN vulnerability2024-06-26
CISA ICS
​Siemens SINAMICS Medium Voltage Products2023-06-15
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party2023-03-16
Debian
CVE-2022-0547: openvpn - OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in externa...2022

🕵️Threat Intelligence

1
Zscaler
Remove Ivanti Zero Day Vulnerabilities with Zscaler Private