Логотип exploitDog
product: "openvpn"
Консоль
Логотип exploitDog

exploitDog

product: "openvpn"

Количество 186

Количество 186

ubuntu логотип

CVE-2024-27903

12 месяцев назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-27903

12 месяцев назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-27903

12 месяцев назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be lo ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-27459

12 месяцев назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2024-27459

12 месяцев назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-27459

12 месяцев назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacke ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-24974

12 месяцев назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-24974

12 месяцев назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-24974

12 месяцев назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVP ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0547

больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-0547

больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-0547

больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2021-3606

почти 4 года назад

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2021-3606

почти 4 года назад

OpenVPN before version 2.5.3 on Windows allows local users to load arb ...

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2021-3547

почти 4 года назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2021-3547

почти 4 года назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middl ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2020-7224

около 5 лет назад

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-27569

около 4 лет назад

Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-20813

почти 2 года назад

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-20813

почти 2 года назад

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
7%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
7%
Низкий
12 месяцев назад
debian логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be lo ...

CVSS3: 9.8
7%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
5%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
5%
Низкий
12 месяцев назад
debian логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacke ...

CVSS3: 7.8
5%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
10%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
10%
Низкий
12 месяцев назад
debian логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVP ...

CVSS3: 7.5
10%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

CVSS3: 7.8
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arb ...

CVSS3: 7.8
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-3547

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-3547

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middl ...

CVSS3: 7.4
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2020-7224

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-27569

Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2020-20813

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2020-20813

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

CVSS3: 7.5
1%
Низкий
почти 2 года назад

Уязвимостей на страницу