Blame
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 1 | # CVE-2020-15078 |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 3 | ## Overview |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 5 | OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 6 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 7 | ## Detailed description |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 8 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 9 | This bug allows - under very specific circumstances - to trick a server using delayed authentication (plugin or management) into returning a PUSH_REPLY before the AUTH_FAILED message, which can possibly be used to gather information about a VPN setup. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 10 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 11 | In combination with "--auth-gen-token" or a user-specific token auth solution it can be possible to get access to a VPN with an otherwise-invalid account. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 12 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 13 | ## Fixed OpenVPN versions |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 14 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 15 | This vulnerability has been fixed in |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 16 | |
| 17 | ||||
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 18 | * release/2.5 |
| 19 | * Commit f7b3bf067ffce72e7de49a4174fd17a3a83f0573 |
|||
| 20 | * Commit 3d18e308c4e7e6f7ab7c2826c70d2d07b031c18a |
|||
| 21 | * Commit 3aca477a1b58714754fea3a26d0892fffc51db6b |
|||
| 22 | * release/2.4 |
|||
| 23 | * Commit 0e5516a9d656ce86f7fb370c824344ea1760c255 |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 24 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 25 | Releases with the fix are: |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 26 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 27 | * OpenVPN 2.5.2 |
| 28 | * OpenVPN 2.4.11 |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 29 | |
| e1ce61 | Samuli Seppänen | 2025-02-27 10:01:50 | 30 | ## Recommendations |
| 31 | ||||
| 32 | If you are not using one of auth-gen-token, plugin, or management in your config, you are safe. In doubt, upgrade. If you know you're using deferred-auth, upgrade. |
