CVE-2020-15078: High severity openvpn monitor vulnerability
Published Apr 26, 2021
·Updated
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Affected Software
18 affected componentsFixes available
ubuntu/openvpn<2.4.4-2ubuntu1.5
2.4.4-2ubuntu1.5
ubuntu/openvpn<2.4.7-1ubuntu2.20.04.2
2.4.7-1ubuntu2.20.04.2
ubuntu/openvpn<2.4.9-3ubuntu1.1
2.4.9-3ubuntu1.1
ubuntu/openvpn<2.5.1-1ubuntu1.1
2.5.1-1ubuntu1.1
ubuntu/openvpn<2.5.1-2
2.5.1-2
ubuntu/openvpn<2.5.1-2
2.5.1-2
ubuntu/openvpn<2.5.2
2.5.2
debian/openvpn
2.5.1-32.6.3-1+deb12u22.6.12-1
OpenVPN OpenVPN<2.4.11
OpenVPN OpenVPN>=2.5.0<2.5.2
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Canonical Ubuntu Linux=20.10
Canonical Ubuntu Linux=21.04
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Apr 26, 2021
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·01:19 PM
Data Sourced
via MITRE·01:19 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 4, 2024
Data Sourced
via Launchpad·01:16 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15078?
CVE-2020-15078 is a vulnerability in OpenVPN 2.5.1 and earlier versions that allows remote attackers to bypass authentication and access control channel data.
2
How severe is CVE-2020-15078?
CVE-2020-15078 has a severity rating of 7.5 (High).
3
What software versions are affected by CVE-2020-15078?
OpenVPN versions 2.4.7-1+deb10u1, 2.5.1-3, 2.6.3-1+deb12u1, and 2.6.3-2 are affected.
4
How can I fix CVE-2020-15078?
To fix CVE-2020-15078, update OpenVPN to version 2.4.7-1+deb10u1, 2.5.1-3, 2.6.3-1+deb12u1, or 2.6.3-2.
5
Where can I find more information about CVE-2020-15078?
You can find more information about CVE-2020-15078 at the following references: [link1], [link2], [link3].