Vulnerabilities > Openvpn > Openvpn Access Server

DATE CVE VULNERABILITY TITLE RISK
2020-02-13 CVE-2020-8953 Improper Authentication vulnerability in Openvpn Access Server 2.8.0
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
network
low complexity
openvpn CWE-287
critical
9.8
2017-05-26 CVE-2017-5868 CRLF Injection vulnerability in Openvpn Access Server 2.1.4
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters in the PATH_INFO to __session_start__/.
network
low complexity
openvpn CWE-93
6.1