VYPR
High severity7.5NVD Advisory· Published Jul 14, 2020· Updated Jun 17, 2026

CVE-2020-15074

CVE-2020-15074

Description

OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.

Affected products

3
  • cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*range: <2.8.4
    • (no CPE)range: <2.8.4, <2.9.5
  • OpenVPN/Access Serverdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.