OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15077
Reference (s):
- https://openvpn.net/security-advisory/access-server-security-update-cve-2020-15077/
- URL: https://openvpn.net/security-advisory/access-server-security-update-cve-2020-15077/
- https://openvpn.net/vpn-server-resources/release-notes/
- URL: https://openvpn.net/vpn-server-resources/release-notes/

