WGSA-2022-00020

OpenVPN Unauthenticated Access To Control Channel Data (CVE-2020-15078)

High Published 2022-07-05Updated 2026-07-27

Summary #

A bug found in OpenVPN that may also apply to Watchguard Mobile VPN could allow a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication which can be used to potentially trigger further information leaks. Based off the limited vulnerability details we believe this vulnerability may impact Fireware OS releases after 12.2 and have updated the version of OpenSSL included in Fireware OS 12.8.1 out of an abundance of caution.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2020-15078 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 12.0, < 12.8.1>= 12.8.1
T15/T35 >= 12.5.0, < 12.5.10>= 12.5.10
FIPS >= 12.3.1, < 12.3.1-b675192>= 12.3.1-b675192

Solution #

Fireware OS 12.8.1, Fireware OS 12.5.10, Fireware OS 12.3.1-b675192

References #