CVE-2021-3547

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
12/07/2021
Last modified:
27/10/2022

Description

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openvpn:openvpn:3.6:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:3.6.1:*:*:*:*:*:*:*