Логотип exploitDog
product: "openvpn"
Консоль
Логотип exploitDog

exploitDog

product: "openvpn"

Количество 191

Количество 191

debian логотип

CVE-2024-28882

больше 1 года назад

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple ex ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-27903

больше 1 года назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-27903

больше 1 года назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-27903

больше 1 года назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be lo ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-27459

больше 1 года назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2024-27459

больше 1 года назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-27459

больше 1 года назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacke ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-24974

больше 1 года назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2024-24974

больше 1 года назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2024-24974

больше 1 года назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVP ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2022-0547

почти 4 года назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-0547

почти 4 года назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-0547

почти 4 года назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2021-3606

больше 4 лет назад

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2021-3606

больше 4 лет назад

OpenVPN before version 2.5.3 on Windows allows local users to load arb ...

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2021-3547

больше 4 лет назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2021-3547

больше 4 лет назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middl ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2020-7224

больше 5 лет назад

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-27569

больше 4 лет назад

Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-20813

больше 2 лет назад

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2024-28882

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple ex ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
7%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
7%
Низкий
больше 1 года назад
debian логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be lo ...

CVSS3: 9.8
7%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
5%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
5%
Низкий
больше 1 года назад
debian логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacke ...

CVSS3: 7.8
5%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
11%
Средний
больше 1 года назад
nvd логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
11%
Средний
больше 1 года назад
debian логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVP ...

CVSS3: 7.5
11%
Средний
больше 1 года назад
ubuntu логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

CVSS3: 9.8
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arb ...

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-3547

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-3547

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middl ...

CVSS3: 7.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-7224

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-27569

Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-20813

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу