Описание
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
A flaw was found in OpenVPN. A remote attacker can exploit this vulnerability by sending a malformed authentication token. This can trigger a reachable assertion when external authentication (external-auth) is enabled, leading to a Denial of Service (DoS) condition for the OpenVPN server.
Отчет
A Moderate denial of service flaw exists in OpenVPN when configured with external-auth. Remote attackers can exploit this by sending a specially crafted authentication token, leading to a reachable assertion and service unavailability. This issue specifically impacts deployments where external authentication is enabled, increasing the attack surface.
Меры по смягчению последствий
To reduce exposure, disable the external-auth feature in OpenVPN if it is not required. This can be done by removing or commenting out the external-auth directive in the OpenVPN configuration file. If external-auth is necessary, restrict network access to the OpenVPN service to trusted clients through firewall rules. A restart of the OpenVPN service is required for configuration changes to take effect, which may temporarily disrupt active connections.
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
5.3 Medium
CVSS3