Vulnerabilities
Vulnerable Software
Openvpn:  >> Openvpn  >> 2.1.28.0  Security Vulnerabilities
OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
CVSS Score
6.5
EPSS Score
0.007
Published
2017-05-15
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.
CVSS Score
5.9
EPSS Score
0.055
Published
2017-01-31
Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.
CVSS Score
6.9
EPSS Score
0.006
Published
2014-08-25
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
CVSS Score
2.6
EPSS Score
0.015
Published
2013-11-18


Contact Us

Shodan ® - All rights reserved