Critical severity9.8NVD Advisory· Published Feb 13, 2020· Updated Jun 17, 2026
CVE-2020-8953
CVE-2020-8953
Description
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
Affected products
3cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*range: >=2.8.0,<2.8.1
- (no CPE)range: <2.8.1
- OpenVPN/Access Serverdescription
Patches
Vulnerability mechanics
References
1- openvpn.net/security-advisories/nvdVendor Advisory
News mentions
0No linked articles in our index yet.