XMLRPC Interface Vulnerability in OpenVPN Access Server
CVE-2020-11462
7.5HIGH
What is CVE-2020-11462?
A vulnerability in OpenVPN Access Server allows for a potential Denial of Service (DoS) condition through the RPC2 interface when malicious XML Entity Expansion (XEE) payloads are sent. This affects versions prior to 2.7.0 and 2.8.x before 2.8.3, putting systems at risk of resource depletion depending on their memory and CPU capacity. Importantly, the default restricted mode of the RPC2 interface is not affected by this issue.