OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
Weakness
The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.
References