Vulnerability Details CVE-2020-15074
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-15074
-
cpe:2.3:a:openvpn:openvpn_access_server:-
-
cpe:2.3:a:openvpn:openvpn_access_server:1.5.6
-
cpe:2.3:a:openvpn:openvpn_access_server:1.8.5
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.10
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.11
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.12
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.17
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.20
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.21
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.24
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.25
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.26
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.5
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.6
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.7
-
cpe:2.3:a:openvpn:openvpn_access_server:2.0.8
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.12
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.4
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.6
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.8
-
cpe:2.3:a:openvpn:openvpn_access_server:2.1.9
-
cpe:2.3:a:openvpn:openvpn_access_server:2.5.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.5.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.6.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.7.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.7.4
-
cpe:2.3:a:openvpn:openvpn_access_server:2.7.5
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.8.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.0
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.1
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.2
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.3
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.4
-
cpe:2.3:a:openvpn:openvpn_access_server:2.9.5