Описание
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
A flaw was found in OpenVPN when using mbedTLS. A remote authenticated user could be misidentified due to the software ignoring the configured X.509 username identity lookup field. This could lead to incorrect user authentication and potential security bypasses.
Отчет
This flaw is rated as Low impact because it requires a remote authenticated user and high attack complexity to exploit. OpenVPN, when configured with mbedTLS, may incorrectly identify users by disregarding the X.509 identity field, potentially leading to unauthorized access under specific, complex conditions.
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authentic ...
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
EPSS
3.1 Low
CVSS3