Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15078

Опубликовано: 26 апр. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

РелизСтатусПримечание
bionic

released

2.4.4-2ubuntu1.5
devel

released

2.5.1-2
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

2.4.4-2ubuntu1.5
esm-infra/focal

not-affected

2.4.7-1ubuntu2.20.04.2
esm-infra/xenial

not-affected

code not present
focal

released

2.4.7-1ubuntu2.20.04.2
groovy

released

2.4.9-3ubuntu1.1
hirsute

released

2.5.1-1ubuntu1.1
impish

released

2.5.1-2

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 7.5
debian
около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass ...

CVSS3: 7.5
github
около 3 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 5.3
fstec
около 4 лет назад

Уязвимость функции отложенной аутентификации deferred_auth программного обеспечения OpenVPN, позволяющая нарушителю вынудить сервер вернуть сообщение PUSH_REPLY c данными о настройках VPN до отправки сообщения AUTH_FAILED

suse-cvrf
около 4 лет назад

Security update for openvpn

5 Medium

CVSS2

7.5 High

CVSS3