CVE Database
/

CVE-2021-3547

Back to search

CVE-2021-3547

Published: Jul 12, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

VendorProductVersions

n/a

OpenVPN 3 Core Library

affected
3.6 and 3.6.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now