CRITICAL · 9.8

CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an exter...

Vulnerability Description

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
OpenvpnOpenvpn>= 2.1.0, < 2.4.12
FedoraprojectFedora34
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-0547?

CVE-2022-0547 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an exter...

How severe is CVE-2022-0547?

CVE-2022-0547 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-0547?

Check the references section above for vendor advisories and patch information. Affected products include: Openvpn Openvpn, Fedoraproject Fedora, Debian Debian Linux.