openvpn openvpn CVE-2021-3547 is a vulnerability in OpenVPN
Published on July 12, 2021

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

NVD

Weakness Type

Authentication Bypass by Primary Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.


Products Associated with CVE-2021-3547

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-3547 are published in OpenVPN:

 

Exploit Probability

EPSS
0.04%
Percentile
10.75%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.