TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-0547

CRITICAL
9.8

Beschreibung

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/18/2022
Zuletzt geandert11/3/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

debian:debian_linuxfedoraproject:fedoraopenvpn:openvpn

Schwachen (CWE)

CWE-305CWE-287

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.