Medium severity5.3NVD Advisory· Published Jun 4, 2021· Updated Jun 17, 2026
CVE-2020-15077
CVE-2020-15077
Description
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Affected products
3cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*range: <=2.8.7
- (no CPE)range: <=2.8.7
- OpenVPN/Access Serverdescription
Patches
Vulnerability mechanics
References
2- openvpn.net/security-advisory/access-server-security-update-cve-2020-15077/nvdVendor Advisory
- openvpn.net/vpn-server-resources/release-notes/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.