VDB

DEBIAN-CVE-2020-15078

DEBIAN-CVE-2020-15078 PUBLISHED CVSS 7.5 HIGH

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:14openvpn0, 0, 0
Debian:11openvpn0, 0, 0
Debian:13openvpn0, 0, 0
Debian:12openvpn0, 0, 0

Timeline

  • Apr 26, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›