OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.
References
Link | Resource |
---|---|
https://openvpn.net/security-advisory/access-server-security-update-cve-2020-15077-cve-2020-36382/ | Vendor Advisory |
https://openvpn.net/vpn-server-resources/release-notes/ | Release Notes Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: OpenVPN
Published: 2021-06-04T10:47:15
Updated: 2021-06-04T10:47:15
Reserved: 2021-05-31T00:00:00
Link: CVE-2020-36382
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-04T11:15:07.790
Modified: 2022-09-20T19:28:19.687
Link: CVE-2020-36382
JSON object: View
Redhat Information
No data.