Vulnerability CVE-2020-36382


Published: 2021-06-04

Description:
OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.

Type:

CWE-754

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Openvpn -> Openvpn access server 

 References:
https://openvpn.net/security-advisory/access-server-security-update-cve-2020-15077-cve-2020-36382/
https://openvpn.net/vpn-server-resources/release-notes/

Copyright 2022, cxsecurity.com

 

Back to Top