CVE-2022-0547: Critical severity openvpn monitor vulnerability
Last updated 24 July 2024
Other sources
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0547?
The severity of CVE-2022-0547 is critical.
What is the impact of CVE-2022-0547?
CVE-2022-0547 enables authentication bypass in OpenVPN plug-ins, allowing external users to gain access with partially correct credentials.
Which versions of OpenVPN are affected by CVE-2022-0547?
OpenVPN versions 2.1 until v2.4.12 and v2.5.6 are affected by CVE-2022-0547.
How can I fix CVE-2022-0547?
Update OpenVPN to a version newer than v2.4.12 or v2.5.6 to fix CVE-2022-0547.
Where can I find more information about CVE-2022-0547?
For more information about CVE-2022-0547, you can refer to the OpenVPN community website and the Debian security announcements.