← Back to browse · API

CVE-2022-0547

Severity
CRITICAL
CVSS
9.8
EPSS
0.03574
Risk score
40.45
CISA KEV
No
PoC
No
Published
2022-03-18
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2022-15669, GHSA-G28R-W65R-H89M
Products
OpenVPN:OpenVPN version 2.1 until version 2.4.12 and 2.5.6.
Sources
euvd EUVD-2022-15669

Description

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

References