CVE-2021-3547
7.4 HIGHOpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an u...
Published: 2021-07-12 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 7.4 HIGH
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- CWE
- CWE-295, CWE-305
Affected products
| Vendor | Product |
|---|---|
| openvpn | openvpn |
Description
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-3547
- [Patch]https://community.openvpn.net/openvpn/wiki/CVE-2021-3547
- [Vendor advisory]https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements
- [Patch]https://community.openvpn.net/openvpn/wiki/CVE-2021-3547
- [Vendor advisory]https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements
Related CVEs
Same vendor
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary command... (7.8 HIGH)
- CVE-2021-3824 — OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL (6.1 MEDIUM)
- CVE-2021-3613 — OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if ... (7.8 HIGH)
- CVE-2021-3606 — OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file... (7.8 HIGH)
- CVE-2014-5455 — Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect vers... (5.3 MEDIUM)
Same CWE
- CVE-2025-71261 — An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere... (8.6 HIGH)
- CVE-2026-9259 — Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier (6.5 MEDIUM)
- CVE-2026-9258 — Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier (6.5 MEDIUM)
- CVE-2026-45388 — In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows imp... (9.1 CRITICAL)
- CVE-2026-45170 — Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validati...