CVE-2021-4234: High severity openvpn access server vulnerability
Published Jul 6, 2022
·Updated
OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack.
Affected Software
1 affected component
OpenVPN OpenVPN Access Server<2.11.0
Event History
Jul 6, 2022
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this OpenVPN Access Server vulnerability?
The vulnerability ID for this OpenVPN Access Server vulnerability is CVE-2021-4234.
2
What is the severity of CVE-2021-4234?
The severity of CVE-2021-4234 is high with a CVSS score of 7.5.
3
Which versions of OpenVPN Access Server are affected by CVE-2021-4234?
OpenVPN Access Server 2.10 and prior versions are affected by CVE-2021-4234.
4
How does CVE-2021-4234 vulnerability work?
CVE-2021-4234 allows an attacker to resend multiple packets in response to a reset packet from the client, resulting in a limited amplification attack.
5
How can I fix CVE-2021-4234?
To fix CVE-2021-4234, you should update OpenVPN Access Server to version 2.11.0 or later.