{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"OpenVPN Unauthenticated Access To Control Channel Data (CVE-2020-15078)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2022-00020","status":"final","version":"17","initial_release_date":"2022-07-05T14:42:51+00:00","current_release_date":"2026-07-27T23:00:44.098131+00:00","revision_history":[{"date":"2022-07-05T14:42:51+00:00","number":"17","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2022-00020"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2020-15078"}],"notes":[{"category":"summary","text":"A bug found in OpenVPN that may also apply to Watchguard Mobile VPN could allow a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication which can be used to potentially trigger further information leaks. Based off the limited vulnerability details we believe this vulnerability may impact Fireware OS releases after 12.2 and have updated the version of OpenSSL included in Fireware OS 12.8.1 out of an abundance of caution.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS (Default)","branches":[{"category":"product_version_range","name":"vers >= 12.0, < 12.8.1","product":{"name":"Fireware OS (Default) vers >= 12.0, < 12.8.1","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"}}]},{"category":"product_name","name":"Fireware OS (FIPS)","branches":[{"category":"product_version_range","name":"vers >= 12.3.1, < 12.3.1-b675192","product":{"name":"Fireware OS (FIPS) vers >= 12.3.1, < 12.3.1-b675192","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"}}]},{"category":"product_name","name":"Fireware OS (T15/T35)","branches":[{"category":"product_version_range","name":"vers >= 12.5.0, < 12.5.10","product":{"name":"Fireware OS (T15/T35) vers >= 12.5.0, < 12.5.10","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"A bug found in OpenVPN that may also apply to Watchguard Mobile VPN could allow a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication which can be used to potentially trigger further information leaks. Based off the limited vulnerability details we believe this vulnerability may impact Fireware OS releases after 12.2 and have updated the version of OpenSSL included in Fireware OS 12.8.1 out of an abundance of caution.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"]},"cve":"CVE-2020-15078","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.8.1 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.3.1-b675192 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.5.10 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"]}]}]}