Good Day everyone!
May I ask a question about the Sophos SSL VPN Client.
One of our customer is using a vulnerability scan tool (Qualys) and reporting is showing me entries from clients with installed Sophos SSL VPN Client.
Firewall Version is SFOS 18.0.5 MR-5-Build586.
When i am downloading the SSL VPN Client from User Portal - OpenVPN Version is 2.3.8.
Any chance for a new Update or do we have to change all VPN Users to Sophos Connect?
-------- INFO for CVE ----------
QID:
375518
Category:
Local
CVE ID:
CVE-2020-15078
Vendor Reference
OpenVpn
Bugtraq ID:
-
Service Modified:
05/06/2021
User Modified:
-
Edited:
No
PCI Vuln:
Yes
IMPACT:
Successful exploitation of this vulnerability allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
SOLUTION:
Users are advised to upgrade to the latest version of the software available. Latest version of the software can be downloaded from OpenVPN
This thread was automatically locked due to age.