OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Link | Tags |
---|---|
https://openvpn.net/vpn-server-resources/release-notes/ | release notes vendor advisory |
https://openvpn.net/security-advisory/access-server-security-update-cve-2020-15077-cve-2020-36382/ | vendor advisory |