PT-2021-12032 · Openvpn · Openvpn Access Server

Published

2021-06-04

·

Updated

2022-09-20

·

CVE-2020-36382

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: OpenVPN Access Server versions 2.7.3 through 2.8.7
Description: The issue allows remote attackers to trigger an assert during the user authentication phase. This occurs when incorrect authentication token data is provided in an early phase of the user authentication, resulting in a denial of service.
Recommendations: For versions 2.7.3 through 2.8.7, as a temporary workaround, consider restricting access to the user authentication phase until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Assertion Failure

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2020-36382

Affected Products

Openvpn Access Server