Логотип exploitDog
bind:"CVE-2018-7544"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2018-7544"

Количество 8

Количество 8

ubuntu логотип

CVE-2018-7544

больше 7 лет назад

** DISPUTED ** A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2018-7544

больше 7 лет назад

A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2018-7544

больше 7 лет назад

A cross-protocol scripting issue was discovered in the management inte ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-9vqg-v7fx-9jvr

около 3 лет назад

** DISPUTED ** A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1576-1

около 4 лет назад

Security update for openvpn

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14723-1

около 4 лет назад

Security update for openvpn-openssl1

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0734-1

около 4 лет назад

Security update for openvpn

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1577-1

около 4 лет назад

Security update for openvpn

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-7544

** DISPUTED ** A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

CVSS3: 9.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-7544

A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning

CVSS3: 9.1
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-7544

A cross-protocol scripting issue was discovered in the management inte ...

CVSS3: 9.1
0%
Низкий
больше 7 лет назад
github логотип
GHSA-9vqg-v7fx-9jvr

** DISPUTED ** A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

CVSS3: 9.1
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:1576-1

Security update for openvpn

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:14723-1

Security update for openvpn-openssl1

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0734-1

Security update for openvpn

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1577-1

Security update for openvpn

около 4 лет назад

Уязвимостей на страницу