CVE-2022-0547: Potential Authentication By-pass with Multiple Deferred Authentication Plug-ins

OpenVPN versions 2.1 up to 2.4.11 and 2.5.5 may allow for an authentication bypass in scenarios where more than one external authentication plug-in utilizes deferred authentication replies. This vulnerability could permit an external user to gain access using only partially correct credentials.

This issue has been addressed in OpenVPN versions 2.4.12 and 2.5.6. In these versions, the OpenVPN server process will terminate and log the following error message:

Exiting due to multiple authentication plug-ins performing deferred authentication. Only one authentication plug-in doing deferred auth is allowed. Ignoring the result and stopping now, the current authentication result is not to be trusted.

MITRE entry for more details: CVE-2022-0547

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9