CVE-2022-0547
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.57% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-305, CWE-287
- Affected
- openvpn/openvpn · fedoraproject/fedora · debian/debian linux
- Source
- security@openvpn.net
References
- https://community.openvpn.net/openvpn/wiki/CVE-2022-0547Vendor Advisory
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncementsVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00002.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFXJ35WKPME4HYNQCQNAJHLCZOJL2SAE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R36OYC5SJ6FLPVAYJYYT4MOJ2I7MGYFF/
- https://openvpn.net/community-downloads/Patch, Vendor Advisory
- https://community.openvpn.net/openvpn/wiki/CVE-2022-0547Vendor Advisory
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncementsVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00002.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00005.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFXJ35WKPME4HYNQCQNAJHLCZOJL2SAE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R36OYC5SJ6FLPVAYJYYT4MOJ2I7MGYFF/
- https://openvpn.net/community-downloads/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.