Vulnerability Details CVE-2020-15074
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-15074
-
cpe:2.3:a:openvpn:openvpn_access_server:-
-
cpe:2.3:a:openvpn:openvpn_access_server:1.5.6
-
cpe:2.3:a:openvpn:openvpn_access_server:1.8.5
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.10
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.11
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.12
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.17
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.20
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.21
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.24
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.25
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.26
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.5
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.6
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.7
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.8
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.12
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.4
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.6
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.8
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.9
-
cpe:2.3:a:openvpn:openvpn_access_server:2.5.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.5.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.6.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.7.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.7.4
-
cpe:2.3:a:openvpn:openvpn_access_server:2.7.5
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.4
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.5