Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

redhat Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2026-84256

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 07 сСнт. 2026
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: redhat
CVSS3: 8.8
EPSS Низкий

ОписаниС

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

A flaw was found in OpenVPN on Windows. An argument parsing issue allows remote authenticated users to execute arbitrary commands by providing a specially crafted certificate subject. This vulnerability could lead to a complete compromise of the affected system.

ΠžΡ‚Ρ‡Π΅Ρ‚

Important: This vulnerability in OpenVPN allows remote authenticated users to execute arbitrary commands through a crafted certificate subject. However, this flaw specifically impacts OpenVPN installations on Windows platforms and does not affect OpenVPN packages provided within Red Hat's Linux-based distributions.

Π”ΠΎΠΏΠΎΠ»Π½ΠΈΡ‚Π΅Π»ΡŒΠ½Π°Ρ информация

Бтатус:

Important
Π”Π΅Ρ„Π΅ΠΊΡ‚:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2529309OpenVPN: OpenVPN: Arbitrary command execution via crafted certificate subject

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 32%
0.00383
Низкий

8.8 High

CVSS3

БвязанныС уязвимости

ubuntu
13 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

nvd
9 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

debian
9 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_a ...

github
9 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 32%
0.00383
Низкий

8.8 High

CVSS3

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2026-84256