Blame

e1ce61 Samuli Seppänen 2025-02-27 10:01:50 1
# CVE-2020-15078 
c4f02d Samuli Seppänen 2025-01-29 08:37:37 2
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 3
## Overview
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 5
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 7
## Detailed description
c4f02d Samuli Seppänen 2025-01-29 08:37:37 8
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 9
This bug allows - under very specific circumstances - to trick a server using delayed authentication (plugin or management) into returning a PUSH_REPLY before the AUTH_FAILED message, which can possibly be used to gather information about a VPN setup.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 10
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 11
In combination with "--auth-gen-token" or a user-specific token auth solution it can be possible to get access to a VPN with an otherwise-invalid account.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 12
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 13
## Fixed OpenVPN versions
c4f02d Samuli Seppänen 2025-01-29 08:37:37 14
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 15
This vulnerability has been fixed in
c4f02d Samuli Seppänen 2025-01-29 08:37:37 16
17
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 18
* release/2.5
19
* Commit f7b3bf067ffce72e7de49a4174fd17a3a83f0573
20
* Commit 3d18e308c4e7e6f7ab7c2826c70d2d07b031c18a
21
* Commit 3aca477a1b58714754fea3a26d0892fffc51db6b
22
* release/2.4
23
* Commit 0e5516a9d656ce86f7fb370c824344ea1760c255
c4f02d Samuli Seppänen 2025-01-29 08:37:37 24
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 25
Releases with the fix are:
c4f02d Samuli Seppänen 2025-01-29 08:37:37 26
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 27
* OpenVPN 2.5.2
28
* OpenVPN 2.4.11
c4f02d Samuli Seppänen 2025-01-29 08:37:37 29
e1ce61 Samuli Seppänen 2025-02-27 10:01:50 30
## Recommendations
31
32
If you are not using one of auth-gen-token, plugin, or management in your config, you are safe. In doubt, upgrade. If you know you're using deferred-auth, upgrade.