CRITICAL
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials
Published Mar 18, 2022
9.8
CRITICALCVSS 3.1
EPSS 3.57%
Description
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
Affected products
- Vendor n/a Product OpenVPN Defaultunknown
Affected
- version 2.1 until version 2.4.12 and 2.5.6.
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | OpenVPN | unknown | Affected
|
Configuration 1
Configuration 2
OR
- 34
- 36
Configuration 3
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://community.openvpn.net/openvpn/wiki/CVE-2022-0547 x_refsource_MISCVendor Advisory
- https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15669 Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00002.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00005.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFXJ35WKPME4HYNQCQNAJHLCZOJL2SAE/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R36OYC5SJ6FLPVAYJYYT4MOJ2I7MGYFF/ vendor-advisoryx_refsource_FEDORA
- https://openvpn.net/community-downloads/ x_refsource_MISCPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://community.openvpn.net/openvpn/wiki/CVE-2022-0547 | x_refsource_MISCVendor Advisory | |
| https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15669 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/05/msg00002.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2025/03/msg00005.html | ||
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GFXJ35WKPME4HYNQCQNAJHLCZOJL2SAE/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R36OYC5SJ6FLPVAYJYYT4MOJ2I7MGYFF/ | vendor-advisoryx_refsource_FEDORA | |
| https://openvpn.net/community-downloads/ | x_refsource_MISCPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OpenVPN
Published Mar 18, 2022
Updated Nov 3, 2025
Reserved Feb 8, 2022
Link CVE-2022-0547
CISA Vulnrichment
Updated Apr 23, 2025
Red Hat
No data
GitHub
No data