Improper Authentication in OpenVPN for Windows - CVE-2022-0547
Published: March 24, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests in external authentication plug-ins when more than one of them makes use of deferred authentication replies. A remote attacker can bypass authentication process and gain unauthorized access to the network with only partially correct credentials.
Affected software
SINAMICS GL150
SINAMICS PERFECT HARMONY GH180 6SR5
SINAMICS SL150
SCALANCE S615
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
openEuler
Securepoint SSL VPN Client
openvpn (Ubuntu package)
openvpn-openssl1
openvpn-openssl1-down-root-plugin
openvpn
openvpn-debugsource
openvpn-debuginfo
openvpn-auth-pam-plugin-debuginfo
openvpn-auth-pam-plugin
openvpn-devel
openvpn-help
openvpn-down-root-plugin-debuginfo
openvpn-down-root-plugin
net-vpn/openvpn
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 VPN Module
RUGGEDCOM RM1224 LTE(4G) NAM
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE M876-3 (EVDO)
SCALANCE M876-4 (EU)
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
How to mitigate CVE-2022-0547
Securepoint SSL VPN Client - update to 2.0.37
openvpn (Ubuntu package) - addressed in versions Ubuntu Pro, 2.4.4-2ubuntu1.7, 2.4.7-1ubuntu2.20.04.4, 2.5.1-3ubuntu1.1
openvpn-openssl1 - update to 2.3.2-0.10.12.1
openvpn-openssl1-down-root-plugin - update to 2.3.2-0.10.12.1
openvpn - addressed in versions 2.3.8-16.29.1, 2.4.3-150000.5.10.1, 2.5.6-150400.3.3.1
openvpn-debugsource - addressed in versions 2.3.8-16.29.1, 2.4.3-150000.5.10.1, 2.5.6-150400.3.3.1
openvpn-debuginfo - addressed in versions 2.3.8-16.29.1, 2.4.3-150000.5.10.1, 2.5.6-150400.3.3.1
openvpn-auth-pam-plugin-debuginfo - addressed in versions 2.3.8-16.29.1, 2.4.3-150000.5.10.1, 2.5.6-150400.3.3.1
openvpn-auth-pam-plugin - addressed in versions 2.3.8-16.29.1, 2.4.3-150000.5.10.1, 2.5.6-150400.3.3.1
openvpn-devel - addressed in versions 2.4.3-150000.5.10.1, 2.5.6-150400.3.3.1
openvpn - update to 2.4.8-8
openvpn-devel - update to 2.4.8-8
openvpn-debuginfo - update to 2.4.8-8
openvpn-debugsource - update to 2.4.8-8
openvpn-help - update to 2.4.8-8
openvpn - addressed in versions 2.4.12-1.el7, 2.4.12-1.el8, 2.5.6-1.el9, 2.5.6-1.fc34, 2.5.6-1.fc35, 2.5.6-1.fc36
openvpn - update to 2.4.12-1.43
openvpn-down-root-plugin-debuginfo - update to 2.5.6-150400.3.3.1
openvpn-down-root-plugin - update to 2.5.6-150400.3.3.1
net-vpn/openvpn - update to 2.6.7
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
IBM MaaS360 VPN Module - update to 2.106.500
IBM MaaS360 Cloud Extender Agent - update to 2.106.500.011
SCALANCE S615 - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M804PB - update to 7.2
External References
Related Security Bulletins
- Authentication bypass in OpenVPN
- Ubuntu update for openvpn
- Multiple vulnerabilities in openvpn-client
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- SUSE update for openvpn
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- SUSE update for openvpn
- SUSE update for openvpn
- SUSE update for openvpn-openssl1
- Amazon Linux AMI update for openvpn
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- openEuler update for openvpn
- Ubuntu update for openvpn
- Gentoo update for OpenVPN
- Fedora 36 update for openvpn
- Fedora 34 update for openvpn
- Fedora 35 update for openvpn
- Fedora EPEL 7 update for openvpn
- Fedora EPEL 8 update for openvpn
- Fedora EPEL 9 update for openvpn