Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63650

Опубликовано: 14 авг. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

A flaw was found in OpenVPN when using mbedTLS. A remote authenticated user could be misidentified due to the software ignoring the configured X.509 username identity lookup field. This could lead to incorrect user authentication and potential security bypasses.

Отчет

This flaw is rated as Low impact because it requires a remote authenticated user and high attack complexity to exploit. OpenVPN, when configured with mbedTLS, may incorrectly identify users by disregarding the X.509 identity field, potentially leading to unauthorized access under specific, complex conditions.

Дополнительная информация

Статус:

Low
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2516214openvpn: mbedtls: OpenVPN: User misidentification via ignored X.509 identity field

EPSS

Процентиль: 13%
0.00228
Низкий

3.1 Low

CVSS3

Связанные уязвимости

ubuntu
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

nvd
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

debian
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authentic ...

github
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

EPSS

Процентиль: 13%
0.00228
Низкий

3.1 Low

CVSS3