Vulnerabilities
Vulnerable Software
Openvpn:  Security Vulnerabilities
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-08-22
OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-07-06
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
CVSS Score
7.5
EPSS Score
0.003
Published
2022-07-06
OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
CVSS Score
7.5
EPSS Score
0.004
Published
2022-07-06
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
CVSS Score
9.8
EPSS Score
0.006
Published
2022-03-18
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-09-23
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.
CVSS Score
7.4
EPSS Score
0.0
Published
2021-07-12
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).
CVSS Score
7.8
EPSS Score
0.001
Published
2021-07-02
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).
CVSS Score
7.8
EPSS Score
0.001
Published
2021-07-02
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
CVSS Score
5.3
EPSS Score
0.001
Published
2021-06-04


Contact Us

Shodan ® - All rights reserved