CVE-2020-8953: Critical severity OpenVPN OpenVPN Access Server vulnerability
Published Feb 13, 2020
·Updated
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
Affected Software
1 affected component
OpenVPN OpenVPN Access Server>=2.8.0<2.8.1
Event History
Feb 13, 2020
CVE Published
via MITRE·03:13 AM
Data Sourced
via MITRE·03:13 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8953?
The severity of CVE-2020-8953 is critical.
2
What is the affected software for CVE-2020-8953?
The affected software for CVE-2020-8953 is OpenVPN Access Server version 2.8.x before 2.8.1.
3
Is LDAP authentication bypass possible in OpenVPN Access Server 2.8.x?
Yes, LDAP authentication bypass is possible in OpenVPN Access Server 2.8.x before 2.8.1 (except when a user is enrolled in two-factor authentication).
4
How can I fix CVE-2020-8953?
To fix CVE-2020-8953, upgrade your OpenVPN Access Server to version 2.8.1 or later.
5
Where can I find more information about CVE-2020-8953?
For more information about CVE-2020-8953, you can refer to the security advisory at https://openvpn.net/security-advisories/