# CVE-2022-0547: Potential Authentication By-pass with Multiple Deferred Authentication Plug-ins
+
# CVE-2022-0547: Potential authentication by-pass with multiple deferred authentication plug-ins
-
OpenVPN versions 2.1 up to 2.4.11 and 2.5.5 may allow for an authentication bypass in scenarios where more than one external authentication plug-in utilizes deferred authentication replies. This vulnerability could permit an external user to gain access using only partially correct credentials.
+
OpenVPN 2.1 up to v2.4.11 and v2.5.5 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
-
This issue has been addressed in OpenVPN versions 2.4.12 and 2.5.6. In these versions, the OpenVPN server process will terminate and log the following error message:
+
This issue is resolved in OpenVPN 2.4.12 and v2.5.6 where the OpenVPN server process will stop running with the following error message in the logs:
```
-
Exiting due to multiple authentication plug-ins performing deferred authentication. Only one authentication plug-in doing deferred auth is allowed. Ignoring the result and stopping now, the current authentication result is not to be trusted.
+
Exiting due to multiple authentication plug-ins performing deferred authentication. Only one authentication plug-in doing deferred auth is allowed. Ignoring the result and stopping now, the current authentication result is not to be trusted.
```
-
MITRE entry for more details: [CVE-2022-0547](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0547)