Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
CVSS Information
N/A
Vulnerability Type
使用假设不可变数据进行的认证绕过
Vulnerability Title
OpenVPN 代码问题漏洞
Vulnerability Description
Openvpn OpenVPN是美国OpenVPN(Openvpn)公司的一个用于创建虚拟专用网络(VPN)加密通道的软件包,它使用OpenSSL库来加密数据与控制信息,并允许创建的VPN使用公开密钥、电子证书或者用户名/密码来进行身份验证。 OpenVPN Access Server 2.8.4之前版本中存在代码问题漏洞,该漏洞源于在进行重新连接时,程序生成了新的用户认证令牌,而不是重新使用现有的令牌。攻击者可利用该漏洞绕过初始的令牌失效时间戳。
CVSS Information
N/A
Vulnerability Type
N/A