Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-0547

Опубликовано: 18 мар. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

РелизСтатусПримечание
bionic

released

2.4.4-2ubuntu1.7
devel

released

2.5.5-1ubuntu3
esm-infra-legacy/trusty

not-affected

2.3.2-7ubuntu3.2+esm1
esm-infra/bionic

not-affected

2.4.4-2ubuntu1.7
esm-infra/focal

not-affected

2.4.7-1ubuntu2.20.04.4
esm-infra/xenial

released

2.3.10-1ubuntu2.2+esm1
focal

released

2.4.7-1ubuntu2.20.04.4
impish

released

2.5.1-3ubuntu1.1
jammy

released

2.5.5-1ubuntu3
kinetic

released

2.5.5-1ubuntu3

Показывать по

EPSS

Процентиль: 63%
0.00452
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
debian
больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

suse-cvrf
около 3 лет назад

Security update for openvpn

suse-cvrf
около 3 лет назад

Security update for openvpn

suse-cvrf
около 3 лет назад

Security update for openvpn-openssl1

EPSS

Процентиль: 63%
0.00452
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3