Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2jp-995w-h282

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

EPSS

Процентиль: 59%
0.00391
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 7.5
nvd
около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 7.5
debian
около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass ...

CVSS3: 5.3
fstec
около 4 лет назад

Уязвимость функции отложенной аутентификации deferred_auth программного обеспечения OpenVPN, позволяющая нарушителю вынудить сервер вернуть сообщение PUSH_REPLY c данными о настройках VPN до отправки сообщения AUTH_FAILED

suse-cvrf
около 4 лет назад

Security update for openvpn

EPSS

Процентиль: 59%
0.00391
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-306