<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenVPN (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/openvpn.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openvpn-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenVPN (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-9560 – Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9560</guid>
    <pubDate>Tue, 26 May 2026 18:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9560</strong></p>
  <p>Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41070 – openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41070</guid>
    <pubDate>Fri, 08 May 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41070</strong></p>
  <p>openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients that do not support WebAuth/SSO (e.g., the openvpn CLI on Linux) are incorrectl…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43254 – In the Linux kernel, the following vulnerability has been resolved:

ovpn: tcp -...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43254</guid>
    <pubDate>Wed, 06 May 2026 12:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43254</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ovpn: tcp - fix packet extraction from stream  When processing TCP stream data in ovpn_tcp_recv, we receive large cloned skbs from __strp_rcv that may contain multiple coalesced packets. The current implementation has two bugs:  1. Header offset overflow: Using pskb_pull with large offsets on    coalesced skbs causes skb->data -…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1490 – An authenticated remote attacker with high privileges can exploit the OpenVPN co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1490</guid>
    <pubDate>Thu, 09 Apr 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1490</strong></p>
  <p>An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30815 – An OS command injection vulnerability in the OpenVPN module
of TP-Link Archer AX...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30815</guid>
    <pubDate>Wed, 08 Apr 2026 19:25:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30815</strong></p>
  <p>An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integri…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34796 – Endian Firewall version 3.3.25 and prior allow authenticated users to execute ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34796</guid>
    <pubDate>Thu, 02 Apr 2026 15:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34796</strong></p>
  <p>Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2670 – A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2670</guid>
    <pubDate>Wed, 18 Feb 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2670</strong></p>
  <p>A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13086 – Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13086</guid>
    <pubDate>Wed, 03 Dec 2025 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13086</strong></p>
  <p>Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12106 – Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12106</guid>
    <pubDate>Mon, 01 Dec 2025 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12106</strong></p>
  <p>Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10680 – OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10680</guid>
    <pubDate>Fri, 24 Oct 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10680</strong></p>
  <p>OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6776 – A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6776</guid>
    <pubDate>Fri, 27 Jun 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6776</strong></p>
  <p>A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the component File Upload. The manipulation of the argument image leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to versi…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54780 – Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54780</guid>
    <pubDate>Wed, 14 May 2025 14:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54780</strong></p>
  <p>Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4877 – OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4877</guid>
    <pubDate>Thu, 03 Apr 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4877</strong></p>
  <p>OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-268</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2704 – OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2704</guid>
    <pubDate>Wed, 02 Apr 2025 21:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2704</strong></p>
  <p>OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39800 – Multiple external config control vulnerabilities exists in the openvpn.cgi openv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39800</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39800</strong></p>
  <p>Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `open_port` POST parameter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39799 – Multiple external config control vulnerabilities exists in the openvpn.cgi openv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39799</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39799</strong></p>
  <p>Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_interface` POST parameter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39798 – Multiple external config control vulnerabilities exists in the openvpn.cgi openv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39798</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39798</strong></p>
  <p>Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_protocol` POST parameter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38666 – An external config control vulnerability exists in the openvpn.cgi openvpn_clien...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38666</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38666</strong></p>
  <p>An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8474 – OpenVPN Connect before version 3.5.0 can contain the configuration profile's cle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8474</guid>
    <pubDate>Mon, 06 Jan 2025 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8474</strong></p>
  <p>OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-5594 – OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5594</guid>
    <pubDate>Mon, 06 Jan 2025 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-5594</strong></p>
  <p>OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-27903 – OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27903</guid>
    <pubDate>Mon, 08 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-27903</strong></p>
  <p>OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-283</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27459 – The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27459</guid>
    <pubDate>Mon, 08 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27459</strong></p>
  <p>The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24974 – The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24974</guid>
    <pubDate>Mon, 08 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24974</strong></p>
  <p>The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-923</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0401 – ASUS routers supporting custom OpenVPN profiles are vulnerable to a code executi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0401</guid>
    <pubDate>Mon, 20 May 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0401</strong></p>
  <p>ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-A…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7235 – The OpenVPN GUI installer before version 2.6.9 did not set the proper access con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7235</guid>
    <pubDate>Wed, 21 Feb 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7235</strong></p>
  <p>The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7245 – The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7245</guid>
    <pubDate>Tue, 20 Feb 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7245</strong></p>
  <p>The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7224 – OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7224</guid>
    <pubDate>Mon, 08 Jan 2024 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7224</strong></p>
  <p>OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46456 – In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46456</guid>
    <pubDate>Tue, 12 Dec 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46456</strong></p>
  <p>In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46455 – In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46455</guid>
    <pubDate>Tue, 12 Dec 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46455</strong></p>
  <p>In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46850 – Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46850</guid>
    <pubDate>Sat, 11 Nov 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46850</strong></p>
  <p>Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46849 – Using the --fragment option in certain configuration setups OpenVPN version 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46849</guid>
    <pubDate>Sat, 11 Nov 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46849</strong></p>
  <p>Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47101 – The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47101</guid>
    <pubDate>Mon, 30 Oct 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47101</strong></p>
  <p>The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41349 – ASUS router RT-AX88U has a vulnerability of using externally controllable format...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41349</guid>
    <pubDate>Mon, 18 Sep 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41349</strong></p>
  <p>ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20813 – Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20813</guid>
    <pubDate>Tue, 22 Aug 2023 19:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20813</strong></p>
  <p>Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46782 – An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46782</guid>
    <pubDate>Sat, 05 Aug 2023 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46782</strong></p>
  <p>An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39986 – A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39986</guid>
    <pubDate>Tue, 01 Aug 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39986</strong></p>
  <p>A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25124 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25124</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25124</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25123 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25123</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25123</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25122 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25122</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25122</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the old_remote_subnet and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25118 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25118</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25118</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the username and the pass…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25117 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25117</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25117</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25116 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25116</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25116</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25115 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25115</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25115</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_ip and the por…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25114 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25114</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25114</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the expert_options variab…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36609 – The affected TBox RTUs run OpenVPN with root privileges and can run user defined...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36609</guid>
    <pubDate>Mon, 03 Jul 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36609</strong></p>
  <p>The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28971 – An Improper Restriction of Communication Channel to Intended Endpoints vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28971</guid>
    <pubDate>Mon, 17 Apr 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28971</strong></p>
  <p>An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Juniper Networks Paragon Active Assurance (PAA) (Formerly Netrounds) allows an attacker to bypass existing firewall rules and limitations used to restrict internal communcations. The Test Agents (TA) Appliance connects to the Control Center (CC) using OpenVPN. TA's are assigned an in…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-923</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44199 – Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44199</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44199</strong></p>
  <p>Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44198 – Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44198</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44198</strong></p>
  <p>Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44197 – Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44197</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44197</strong></p>
  <p>Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44196 – Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44196</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44196</strong></p>
  <p>Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27406 – An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27406</guid>
    <pubDate>Fri, 14 Oct 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27406</strong></p>
  <p>An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This could result in the attacker achieving execution with privileges of a SYSTEM user.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34821 – A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34821</guid>
    <pubDate>Tue, 12 Jul 2022 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34821</strong></p>
  <p>A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2), SCALANCE M826-2 SHDSL…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4234 – OpenVPN Access Server 2.10 and prior versions are susceptible to resending multi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4234</guid>
    <pubDate>Wed, 06 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4234</strong></p>
  <p>OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-406</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33738 – OpenVPN Access Server before 2.11 uses a weak random generator used to create us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33738</guid>
    <pubDate>Wed, 06 Jul 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33738</strong></p>
  <p>OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33737 – The OpenVPN Access Server installer creates a log file readable for everyone, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33737</guid>
    <pubDate>Wed, 06 Jul 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33737</strong></p>
  <p>The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-708</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24299 – Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24299</guid>
    <pubDate>Thu, 31 Mar 2022 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24299</strong></p>
  <p>Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-0547 – OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in externa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0547</guid>
    <pubDate>Fri, 18 Mar 2022 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-0547</strong></p>
  <p>OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3773 – A flaw in netfilter could allow a network-connected attacker to infer openvpn co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3773</guid>
    <pubDate>Wed, 16 Feb 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3773</strong></p>
  <p>A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20145 – Gryphon Tower routers contain an unprotected openvpn configuration file which ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20145</guid>
    <pubDate>Thu, 09 Dec 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20145</strong></p>
  <p>Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31606 – furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31606</guid>
    <pubDate>Mon, 27 Sep 2021 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31606</strong></p>
  <p>furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31605 – furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the Open...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31605</guid>
    <pubDate>Mon, 27 Sep 2021 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31605</strong></p>
  <p>furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33526 – In MB connect line mbDIALUP versions &lt;= 3.9R0.0 a low privileged local attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33526</guid>
    <pubDate>Mon, 02 Aug 2021 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33526</strong></p>
  <p>In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3547 – OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3547</guid>
    <pubDate>Mon, 12 Jul 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3547</strong></p>
  <p>OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3613 – OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3613</guid>
    <pubDate>Fri, 02 Jul 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3613</strong></p>
  <p>OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3606 – OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dyn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3606</guid>
    <pubDate>Fri, 02 Jul 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3606</strong></p>
  <p>OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35523 – Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35523</guid>
    <pubDate>Mon, 28 Jun 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35523</strong></p>
  <p>Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36382 – OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an asser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36382</guid>
    <pubDate>Fri, 04 Jun 2021 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36382</strong></p>
  <p>OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27518 – All versions of Windscribe VPN for Mac and Windows &lt;= v2.02.10 contain a local p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27518</guid>
    <pubDate>Tue, 04 May 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27518</strong></p>
  <p>All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27519 – Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27519</guid>
    <pubDate>Fri, 30 Apr 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27519</strong></p>
  <p>Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the log and log-append along with log injection to create or append to privileged script files and execute code as root/SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15078 – OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15078</guid>
    <pubDate>Mon, 26 Apr 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15078</strong></p>
  <p>OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15075 – OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15075</guid>
    <pubDate>Tue, 30 Mar 2021 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15075</strong></p>
  <p>OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27649 – Improper certificate validation vulnerability in OpenVPN client in Synology Rout...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27649</guid>
    <pubDate>Thu, 29 Oct 2020 09:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27649</strong></p>
  <p>Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27648 – Improper certificate validation vulnerability in OpenVPN client in Synology Disk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27648</guid>
    <pubDate>Thu, 29 Oct 2020 09:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27648</strong></p>
  <p>Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15590 – A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15590</guid>
    <pubDate>Mon, 14 Sep 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15590</strong></p>
  <p>A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. Since 1.5, PIA has supported a “split tunnel” OpenVPN bypass option. The PIA killswitch & associated iptables firewall is designed to protect you while using the Internet.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15074 – OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15074</guid>
    <pubDate>Tue, 14 Jul 2020 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15074</strong></p>
  <p>OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15473 – In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15473</guid>
    <pubDate>Wed, 01 Jul 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15473</strong></p>
  <p>In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11462 – An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11462</guid>
    <pubDate>Mon, 04 May 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11462</strong></p>
  <p>An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sending an XML Entity Expansion (XEE) payload to the XMLRPC based RPC2 interface. The duration of the DoS state depends on available memory and CPU speed. The default restricted mode of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-776</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7224 – The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7224</guid>
    <pubDate>Thu, 16 Apr 2020 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7224</strong></p>
  <p>The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5739 – Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5739</guid>
    <pubDate>Tue, 14 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5739</strong></p>
  <p>Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9442 – OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9442</guid>
    <pubDate>Fri, 28 Feb 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9442</strong></p>
  <p>OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8953 – OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (exce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8953</guid>
    <pubDate>Thu, 13 Feb 2020 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8953</strong></p>
  <p>OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5180 – Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5180</guid>
    <pubDate>Tue, 14 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5180</strong></p>
  <p>Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection is initiated using a TLS/SSL client profile, the privileges are dropped, and the library will be loaded, resulting in arbitrary code execut…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-14929 – An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14929</guid>
    <pubDate>Mon, 28 Oct 2019 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-14929</strong></p>
  <p>An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14657 – Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14657</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14657</strong></p>
  <p>Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password replacement and arbitrary code execution as root.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12579 – A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12579</guid>
    <pubDate>Thu, 11 Jul 2019 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12579</strong></p>
  <p>A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update the system configuration. These parameters are passed to operating system comman…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12578 – A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12578</guid>
    <pubDate>Thu, 11 Jul 2019 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12578</strong></p>
  <p>A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /opt/pia/openvpn-64/openvpn, passing the parameters provided from the command line. Care was taken to programmatically disable potentially da…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12577 – A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12577</guid>
    <pubDate>Thu, 11 Jul 2019 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12577</strong></p>
  <p>A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file creation mask (umask) is not reset, the umask value is inherited from the calling p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12576 – A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12576</guid>
    <pubDate>Thu, 11 Jul 2019 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12576</strong></p>
  <p>A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called usin…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12573 – A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12573</guid>
    <pubDate>Thu, 11 Jul 2019 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12573</strong></p>
  <p>A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is not sanitized, which allows a local unprivileged user to overwrite arbitrary fi…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6628 – On BIG-IP PEM 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, under certain conditions, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6628</guid>
    <pubDate>Wed, 03 Jul 2019 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6628</strong></p>
  <p>On BIG-IP PEM 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, under certain conditions, the TMM process may terminate and restart while processing BIG-IP PEM traffic with the OpenVPN classifier.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11479 – The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11479</guid>
    <pubDate>Fri, 25 May 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11479</strong></p>
  <p>The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). There is no validation of the program name before constructing the lpCommand…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10647 – SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10647</guid>
    <pubDate>Wed, 02 May 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10647</strong></p>
  <p>SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service executes "openvpn.exe" using OpenVPN config files located within the current user's %LOCALAPPDATA%\SaferVPN\OvpnConfig directory. An authenticated attacker may modify these configuration files to specify a dynamic library plugin that should run for…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10646 – CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10646</guid>
    <pubDate>Wed, 02 May 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10646</strong></p>
  <p>CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "ConnectToVpnServer" method accepts a "connectionParams" argument that provides attacker control of the OpenVPN command line. An a…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10645 – Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege esca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10645</guid>
    <pubDate>Wed, 02 May 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10645</strong></p>
  <p>Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. The "SetProperty" method allows an attacker to configure the "AdditionalOpenVpnParameters" property and control the OpenVPN command line. Using the…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-9336 – openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9336</guid>
    <pubDate>Tue, 01 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-9336</strong></p>
  <p>openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-10381 – TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10381</guid>
    <pubDate>Thu, 26 Apr 2018 00:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-10381</strong></p>
  <p>TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "OpenVPNConnect" method accepts a server list argument that provides attacker control of the OpenVPN command line. An atta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10204 – PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10204</guid>
    <pubDate>Wed, 18 Apr 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10204</strong></p>
  <p>PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When configured to use the OpenVPN protocol, the "sevpnclient" service executes "openvpn.exe" using the OpenVPN config file located at %PROGRAMDATA%\purevpn\config\config.ovpn. This file allows "Write" permissions to users in the "Everyone" group. An authenticated attacker may modify t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-10170 – NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10170</guid>
    <pubDate>Mon, 16 Apr 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-10170</strong></p>
  <p>NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can sp…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-10169 – ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10169</guid>
    <pubDate>Mon, 16 Apr 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-10169</strong></p>
  <p>ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can s…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10066 – An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server cert...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10066</guid>
    <pubDate>Fri, 13 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10066</strong></p>
  <p>An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffic to act as a malicious OpenVPN server. This may allow the attacker to gain access to the client's internal network (for example, at site-to-site tunnels).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10066">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
