CVE-2020-15078: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 20.04 only; version 20.10 only; version 21.04 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
- Openvpn Openvpn: before 2.4.11 (fixed in 2.4.11); from 2.5.0, before 2.5.2 (fixed in 2.5.2)
Published 2021-04-26. Last modified 2026-06-17.