Логотип exploitDog
product: "openvpn"
Консоль
Логотип exploitDog

exploitDog

product: "openvpn"

Количество 186

Количество 186

debian логотип

CVE-2020-20813

почти 2 года назад

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers t ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-15078

около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-15078

около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-15078

около 4 лет назад

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-11810

около 5 лет назад

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2020-11810

около 5 лет назад

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2020-11810

около 5 лет назад

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2018-9336

около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2018-9336

около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2018-9336

около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2018-7544

больше 7 лет назад

** DISPUTED ** A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2018-7544

больше 7 лет назад

A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2018-7544

больше 7 лет назад

A cross-protocol scripting issue was discovered in the management inte ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2017-7522

почти 8 лет назад

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2017-7522

почти 8 лет назад

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7522

почти 8 лет назад

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2017-7522

почти 8 лет назад

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to deni ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-7521

почти 8 лет назад

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2017-7521

почти 8 лет назад

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7521

почти 8 лет назад

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2020-20813

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers t ...

CVSS3: 7.5
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2020-15078

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2020-15078

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2020-15078

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass ...

CVSS3: 7.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2020-11810

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.

CVSS3: 3.7
2%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-11810

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.

CVSS3: 3.7
2%
Низкий
около 5 лет назад
debian логотип
CVE-2020-11810

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can ...

CVSS3: 3.7
2%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2018-9336

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

CVSS3: 7.8
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-9336

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

CVSS3: 7.8
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-9336

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x ...

CVSS3: 7.8
0%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-7544

** DISPUTED ** A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

CVSS3: 9.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-7544

A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning

CVSS3: 9.1
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-7544

A cross-protocol scripting issue was discovered in the management inte ...

CVSS3: 9.1
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-7522

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVSS3: 6.5
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2017-7522

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-7522

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVSS3: 6.5
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-7522

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to deni ...

CVSS3: 6.5
1%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-7521

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

CVSS3: 5.9
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2017-7521

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-7521

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

CVSS3: 5.9
1%
Низкий
почти 8 лет назад

Уязвимостей на страницу