@jimp
Hi,
thanks for the answers !
Regarding the fact that the pfsense 2.6.0 CE version is impacted, for my part I was able to confirm that last week that on one of my firewalls in 2.6.0 not up to date I had available the 2.5.4 package of openvpn while today I have version 2.6.4.
What is strange is that as https://cve.mitre.org/ indicates, only versions 2.6.0 to 2.6.6 are impacted...
09adf418-f563-483c-a369-5e4d60d0cff7-image.png
0ee2dbd6-cc83-41b3-9214-51f9a43b7792-image.png
911df671-4911-41c9-8a99-96362055474f-image.png
49e14baa-a9bd-40b3-997f-36603c82f552-image.png
To conclude, you must upgrade to pfsense CE version 2.7.1