ZeroHour

CVE-2020-15074

CVSS 3.1
7.5 high
EPSS
1%p62
Published
()
Modified
Description

OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.

Vendors
openvpn
Products
openvpn access server
Weakness
CWE-302, CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.