CVE-2020-11462
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sending an XML Entity Expansion (XEE) payload to the XMLRPC based RPC2 interface. The duration of the DoS state depends on available memory and CPU speed. The default restricted mode of the RPC2 interface is NOT vulnerable.
Se ha descubierto un problema en OpenVPN Access Server versiones anteriores a la versión 2.7.0 y versiones 2.8.x anteriores a la versión 2.8.3. Con la interfaz RPC2 con todas las funcionalidades activadas, es posible conseguir un estado DoS temporal de la interfaz de administración cuando se envía una carga útil XML Entity Expansion (XEE) hacia la interfaz RPC2 basada en XMLRPC. La duración del estado DoS depende de la memoria disponible y de la velocidad de una CPU. El modo restringido por defecto de la interfaz RPC2 NO es vulnerable.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-01 CVE Reserved
- 2020-05-04 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openvpn Search vendor "Openvpn" | Openvpn Access Server Search vendor "Openvpn" for product "Openvpn Access Server" | < 2.7.0 Search vendor "Openvpn" for product "Openvpn Access Server" and version " < 2.7.0" | - |
Affected
| ||||||
Openvpn Search vendor "Openvpn" | Openvpn Access Server Search vendor "Openvpn" for product "Openvpn Access Server" | >= 2.8.0 <= 2.8.3 Search vendor "Openvpn" for product "Openvpn Access Server" and version " >= 2.8.0 <= 2.8.3" | - |
Affected
|