CVE-2021-4234

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/07/2022
Last modified:
14/07/2022

Description

OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:* 2.11.0 (excluding)