Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13122

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

A flaw was found in OpenVPN. A remote attacker can exploit this vulnerability by sending a malformed authentication token. This can trigger a reachable assertion when external authentication (external-auth) is enabled, leading to a Denial of Service (DoS) condition for the OpenVPN server.

Отчет

A Moderate denial of service flaw exists in OpenVPN when configured with external-auth. Remote attackers can exploit this by sending a specially crafted authentication token, leading to a reachable assertion and service unavailability. This issue specifically impacts deployments where external authentication is enabled, increasing the attack surface.

Меры по смягчению последствий

To reduce exposure, disable the external-auth feature in OpenVPN if it is not required. This can be done by removing or commenting out the external-auth directive in the OpenVPN configuration file. If external-auth is necessary, restrict network access to the OpenVPN service to trusted clients through firewall rules. A restart of the OpenVPN service is required for configuration changes to take effect, which may temporarily disrupt active connections.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
24 дня назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
nvd
24 дня назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
debian
24 дня назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...

CVSS3: 5.3
github
24 дня назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

5.3 Medium

CVSS3