PT-2021-12032 · Openvpn · Openvpn Access Server
Published
2021-06-04
·
Updated
2022-09-20
·
CVE-2020-36382
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
OpenVPN Access Server versions 2.7.3 through 2.8.7
Description:
The issue allows remote attackers to trigger an assert during the user authentication phase. This occurs when incorrect authentication token data is provided in an early phase of the user authentication, resulting in a denial of service.
Recommendations:
For versions 2.7.3 through 2.8.7, as a temporary workaround, consider restricting access to the user authentication phase until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Assertion Failure
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openvpn Access Server