Vulnerability Description
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openvpn | Openvpn | >= 2.1.0, < 2.4.12 |
| Fedoraproject | Fedora | 34 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://community.openvpn.net/openvpn/wiki/CVE-2022-0547Vendor Advisory
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncementsVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00002.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://openvpn.net/community-downloads/PatchVendor Advisory
- https://community.openvpn.net/openvpn/wiki/CVE-2022-0547Vendor Advisory
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncementsVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00002.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00005.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://openvpn.net/community-downloads/PatchVendor Advisory
FAQ
What is CVE-2022-0547?
CVE-2022-0547 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an exter...
How severe is CVE-2022-0547?
CVE-2022-0547 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-0547?
Check the references section above for vendor advisories and patch information. Affected products include: Openvpn Openvpn, Fedoraproject Fedora, Debian Debian Linux.