CVE-2020-15074: High severity openvpn access server vulnerability
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15074?
CVE-2020-15074 is a vulnerability in OpenVPN Access Server older than version 2.8.4 and version 2.9.5 that allows circumvention of token expiry timestamp.
How does CVE-2020-15074 affect OpenVPN Access Server?
CVE-2020-15074 affects OpenVPN Access Server older than version 2.8.4 and version 2.9.5, where it generates new user authentication tokens instead of reusing existing ones on reconnect.
What is the severity of CVE-2020-15074?
The severity of CVE-2020-15074 is high (7.5).
How can I fix CVE-2020-15074?
To fix CVE-2020-15074, you need to upgrade your OpenVPN Access Server to version 2.8.4 or higher, or version 2.9.6 or higher.
Where can I find more information about CVE-2020-15074?
You can find more information about CVE-2020-15074 in the release notes of OpenVPN Access Server: https://openvpn.net/vpn-server-resources/release-notes/