CVE-2020-36382: Openvpn Access Server

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.

Affected products

  • Openvpn Openvpn Access Server: from 2.7.3, up to and including 2.8.7

Published 2021-06-04. Last modified 2026-06-17.