<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenVPN</title>
  <link>https://cvedaily.com/pages/tags/openvpn.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openvpn.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenVPN</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2026-45918 – In the Linux kernel, the following vulnerability has been resolved:

ovpn: tcp -...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45918</guid>
    <pubDate>Wed, 27 May 2026 14:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-45918</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ovpn: tcp - don't deref NULL sk_socket member after tcp_close()  When deleting a peer in case of keepalive expiration, the peer is removed from the OpenVPN hashtable and is temporary inserted in a "release list" for further processing.  This happens in: ovpn_peer_keepalive_work()   unlock_ovpn(release_list)  This processing incl…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9560 – Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9560</guid>
    <pubDate>Tue, 26 May 2026 18:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9560</strong></p>
  <p>Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41070 – openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41070</guid>
    <pubDate>Fri, 08 May 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41070</strong></p>
  <p>openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients that do not support WebAuth/SSO (e.g., the openvpn CLI on Linux) are incorrectl…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43254 – In the Linux kernel, the following vulnerability has been resolved:

ovpn: tcp -...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43254</guid>
    <pubDate>Wed, 06 May 2026 12:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43254</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ovpn: tcp - fix packet extraction from stream  When processing TCP stream data in ovpn_tcp_recv, we receive large cloned skbs from __strp_rcv that may contain multiple coalesced packets. The current implementation has two bugs:  1. Header offset overflow: Using pskb_pull with large offsets on    coalesced skbs causes skb->data -…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31893 – Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31893</guid>
    <pubDate>Tue, 05 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31893</strong></p>
  <p>Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink following vulnerability in tunnelblick-helper, reachable through the world-accessible tunnelblickd Unix socket. The socket is configured with mode 0666, allowing any local user to connect. No authorization ch…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-42611 – RouterOS provides various services that rely on correct
verification of client a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-42611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-42611</guid>
    <pubDate>Tue, 05 May 2026 11:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-42611</strong></p>
  <p>RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others.    The vulnerability lies in shared certificate validation logic which uses the system certificate store that is shared and equally trusted by all system services. This causes…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-42611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1490 – An authenticated remote attacker with high privileges can exploit the OpenVPN co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1490</guid>
    <pubDate>Thu, 09 Apr 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1490</strong></p>
  <p>An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30817 – An external configuration control vulnerability in the OpenVPN module of TP-Link...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30817</guid>
    <pubDate>Wed, 08 Apr 2026 19:25:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30817</strong></p>
  <p>An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30816 – An external control of configuration vulnerability in the OpenVPN module of TP-L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30816</guid>
    <pubDate>Wed, 08 Apr 2026 19:25:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30816</strong></p>
  <p>An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30815 – An OS command injection vulnerability in the OpenVPN module
of TP-Link Archer AX...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30815</guid>
    <pubDate>Wed, 08 Apr 2026 19:25:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30815</strong></p>
  <p>An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integri…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34796 – Endian Firewall version 3.3.25 and prior allow authenticated users to execute ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34796</guid>
    <pubDate>Thu, 02 Apr 2026 15:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34796</strong></p>
  <p>Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25429 – Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25429</guid>
    <pubDate>Thu, 19 Feb 2026 13:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25429</strong></p>
  <p>Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the openvpn_advanced endpoint. Attackers can inject JavaScript code through the GLOBAL_NETWORKS and GLOBAL_DNS parameters via POST requests to execute arbitrary scripts in users' browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25428 – Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25428</guid>
    <pubDate>Thu, 19 Feb 2026 13:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25428</strong></p>
  <p>Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vulnerabilities in the openvpn_users endpoint that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted POST requests with script payloads in the username, remotenets, explicitroutes, static_ip, custom_dns, or custom_domain parameters to execute arbitrary JavaScript in users' b…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2670 – A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2670</guid>
    <pubDate>Wed, 18 Feb 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2670</strong></p>
  <p>A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-15497 – Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15497</guid>
    <pubDate>Fri, 30 Jan 2026 18:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-15497</strong></p>
  <p>Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13086 – Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13086</guid>
    <pubDate>Wed, 03 Dec 2025 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13086</strong></p>
  <p>Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13751 – Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13751</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13751</strong></p>
  <p>Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12106 – Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12106</guid>
    <pubDate>Mon, 01 Dec 2025 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12106</strong></p>
  <p>Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-34304 – IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34304</guid>
    <pubDate>Tue, 28 Oct 2025 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-34304</strong></p>
  <p>IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL query used when viewing OpenVPN connection logs via the CONNECTION_NAME parameter. When viewing a range of OpenVPN connection logs, the application issues an HTTP POST request to the Request-URI /cgi-bin/logs.cgi/ovpnclients.dat and inserts the value of…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50055 – Cross-site scripting (XSS) vulnerability in the SAML Authentication module in Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50055</guid>
    <pubDate>Mon, 27 Oct 2025 14:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50055</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10680 – OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10680</guid>
    <pubDate>Fri, 24 Oct 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10680</strong></p>
  <p>OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24292 – A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24292</guid>
    <pubDate>Sun, 29 Jun 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24292</strong></p>
  <p>A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s  MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6776 – A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6776</guid>
    <pubDate>Fri, 27 Jun 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6776</strong></p>
  <p>A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the component File Upload. The manipulation of the argument image leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to versi…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6775 – A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6775</guid>
    <pubDate>Fri, 27 Jun 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6775</strong></p>
  <p>A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the component User Creation Endpoint. The manipulation of the argument Username leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrad…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50054 – Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50054</guid>
    <pubDate>Fri, 20 Jun 2025 07:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50054</strong></p>
  <p>Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4412 – On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4412</guid>
    <pubDate>Tue, 27 May 2025 10:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4412</strong></p>
  <p>On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted permissions for file resources apply. Access to ot…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3908 – The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3908</guid>
    <pubDate>Mon, 19 May 2025 15:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3908</strong></p>
  <p>The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54780 – Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54780</guid>
    <pubDate>Wed, 14 May 2025 14:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54780</strong></p>
  <p>Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4877 – OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4877</guid>
    <pubDate>Thu, 03 Apr 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4877</strong></p>
  <p>OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-268</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2704 – OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2704</guid>
    <pubDate>Wed, 02 Apr 2025 21:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2704</strong></p>
  <p>OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-23384 – A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23384</guid>
    <pubDate>Tue, 11 Mar 2025 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-23384</strong></p>
  <p>A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.2.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.2.1), SCALANCE M826-2 SHDSL-Router…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-187</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-5198 – OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5198</guid>
    <pubDate>Wed, 15 Jan 2025 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-5198</strong></p>
  <p>OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39800 – Multiple external config control vulnerabilities exists in the openvpn.cgi openv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39800</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39800</strong></p>
  <p>Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `open_port` POST parameter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39799 – Multiple external config control vulnerabilities exists in the openvpn.cgi openv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39799</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39799</strong></p>
  <p>Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_interface` POST parameter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39798 – Multiple external config control vulnerabilities exists in the openvpn.cgi openv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39798</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39798</strong></p>
  <p>Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_protocol` POST parameter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38666 – An external config control vulnerability exists in the openvpn.cgi openvpn_clien...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38666</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38666</strong></p>
  <p>An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8474 – OpenVPN Connect before version 3.5.0 can contain the configuration profile's cle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8474</guid>
    <pubDate>Mon, 06 Jan 2025 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8474</strong></p>
  <p>OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-5594 – OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5594</guid>
    <pubDate>Mon, 06 Jan 2025 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-5594</strong></p>
  <p>OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-50998 – Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50998</guid>
    <pubDate>Tue, 05 Nov 2024 15:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-50998</strong></p>
  <p>Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-28882 – OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notific...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28882</guid>
    <pubDate>Mon, 08 Jul 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-28882</strong></p>
  <p>OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-27903 – OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27903</guid>
    <pubDate>Mon, 08 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-27903</strong></p>
  <p>OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-283</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27459 – The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27459</guid>
    <pubDate>Mon, 08 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27459</strong></p>
  <p>The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24974 – The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24974</guid>
    <pubDate>Mon, 08 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24974</strong></p>
  <p>The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-923</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-28820 – Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28820</guid>
    <pubDate>Thu, 27 Jun 2024 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-28820</strong></p>
  <p>Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a buffer overflow.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0401 – ASUS routers supporting custom OpenVPN profiles are vulnerable to a code executi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0401</guid>
    <pubDate>Mon, 20 May 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0401</strong></p>
  <p>ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-A…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6247 – The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not prope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6247</guid>
    <pubDate>Thu, 29 Feb 2024 01:42:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6247</strong></p>
  <p>The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7235 – The OpenVPN GUI installer before version 2.6.9 did not set the proper access con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7235</guid>
    <pubDate>Wed, 21 Feb 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7235</strong></p>
  <p>The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7245 – The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7245</guid>
    <pubDate>Tue, 20 Feb 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7245</strong></p>
  <p>The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7224 – OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7224</guid>
    <pubDate>Mon, 08 Jan 2024 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7224</strong></p>
  <p>OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46456 – In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46456</guid>
    <pubDate>Tue, 12 Dec 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46456</strong></p>
  <p>In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46455 – In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46455</guid>
    <pubDate>Tue, 12 Dec 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46455</strong></p>
  <p>In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46850 – Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46850</guid>
    <pubDate>Sat, 11 Nov 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46850</strong></p>
  <p>Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46849 – Using the --fragment option in certain configuration setups OpenVPN version 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46849</guid>
    <pubDate>Sat, 11 Nov 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46849</strong></p>
  <p>Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47101 – The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47101</guid>
    <pubDate>Mon, 30 Oct 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47101</strong></p>
  <p>The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3761 – OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3761</guid>
    <pubDate>Tue, 17 Oct 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3761</strong></p>
  <p>OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentials</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41349 – ASUS router RT-AX88U has a vulnerability of using externally controllable format...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41349</guid>
    <pubDate>Mon, 18 Sep 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41349</strong></p>
  <p>ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-20813 – Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-20813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-20813</guid>
    <pubDate>Tue, 22 Aug 2023 19:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-20813</strong></p>
  <p>Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46782 – An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46782</guid>
    <pubDate>Sat, 05 Aug 2023 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46782</strong></p>
  <p>An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39986 – A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39986</guid>
    <pubDate>Tue, 01 Aug 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39986</strong></p>
  <p>A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25124 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25124</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25124</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25123 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25123</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25123</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25122 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25122</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25122</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the old_remote_subnet and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25118 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25118</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25118</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the username and the pass…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25117 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25117</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25117</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25116 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25116</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25116</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25115 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25115</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25115</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_ip and the por…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25114 – Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Miles...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25114</guid>
    <pubDate>Thu, 06 Jul 2023 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25114</strong></p>
  <p>Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the expert_options variab…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36609 – The affected TBox RTUs run OpenVPN with root privileges and can run user defined...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36609</guid>
    <pubDate>Mon, 03 Jul 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36609</strong></p>
  <p>The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-33621 – GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token int...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33621</guid>
    <pubDate>Tue, 13 Jun 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-33621</strong></p>
  <p>GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-32348 – Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32348</guid>
    <pubDate>Mon, 22 May 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-32348</strong></p>
  <p>Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that uses OpenVPN. It connects new devices in a manner that allows the new device to communicate with all Teltonika devices connected to the VPN. The OpenVPN server also allows users to route through it. An attacker could route a connection to a remote s…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28971 – An Improper Restriction of Communication Channel to Intended Endpoints vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28971</guid>
    <pubDate>Mon, 17 Apr 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28971</strong></p>
  <p>An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Juniper Networks Paragon Active Assurance (PAA) (Formerly Netrounds) allows an attacker to bypass existing firewall rules and limitations used to restrict internal communcations. The Test Agents (TA) Appliance connects to the Control Center (CC) using OpenVPN. TA's are assigned an in…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-923</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24181 – LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24181</guid>
    <pubDate>Mon, 10 Apr 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24181</strong></p>
  <p>LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44199 – Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44199</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44199</strong></p>
  <p>Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44198 – Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44198</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44198</strong></p>
  <p>Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44197 – Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44197</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44197</strong></p>
  <p>Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44196 – Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44196</guid>
    <pubDate>Tue, 22 Nov 2022 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44196</strong></p>
  <p>Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27406 – An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27406</guid>
    <pubDate>Fri, 14 Oct 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27406</strong></p>
  <p>An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This could result in the attacker achieving execution with privileges of a SYSTEM user.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34821 – A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34821</guid>
    <pubDate>Tue, 12 Jul 2022 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34821</strong></p>
  <p>A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2), SCALANCE M826-2 SHDSL…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4234 – OpenVPN Access Server 2.10 and prior versions are susceptible to resending multi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4234</guid>
    <pubDate>Wed, 06 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4234</strong></p>
  <p>OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-406</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33738 – OpenVPN Access Server before 2.11 uses a weak random generator used to create us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33738</guid>
    <pubDate>Wed, 06 Jul 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33738</strong></p>
  <p>OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33737 – The OpenVPN Access Server installer creates a log file readable for everyone, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33737</guid>
    <pubDate>Wed, 06 Jul 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33737</strong></p>
  <p>The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-708</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-25166 – An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to includ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25166</guid>
    <pubDate>Thu, 14 Apr 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-25166</strong></p>
  <p>An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24299 – Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24299</guid>
    <pubDate>Thu, 31 Mar 2022 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24299</strong></p>
  <p>Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-0547 – OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in externa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0547</guid>
    <pubDate>Fri, 18 Mar 2022 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-0547</strong></p>
  <p>OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3773 – A flaw in netfilter could allow a network-connected attacker to infer openvpn co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3773</guid>
    <pubDate>Wed, 16 Feb 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3773</strong></p>
  <p>A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20145 – Gryphon Tower routers contain an unprotected openvpn configuration file which ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20145</guid>
    <pubDate>Thu, 09 Dec 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20145</strong></p>
  <p>Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31606 – furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31606</guid>
    <pubDate>Mon, 27 Sep 2021 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31606</strong></p>
  <p>furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31605 – furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the Open...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31605</guid>
    <pubDate>Mon, 27 Sep 2021 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31605</strong></p>
  <p>furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-31604 – furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31604</guid>
    <pubDate>Mon, 27 Sep 2021 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-31604</strong></p>
  <p>furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3824 – OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3824</guid>
    <pubDate>Thu, 23 Sep 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3824</strong></p>
  <p>OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-84</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33526 – In MB connect line mbDIALUP versions &lt;= 3.9R0.0 a low privileged local attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33526</guid>
    <pubDate>Mon, 02 Aug 2021 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33526</strong></p>
  <p>In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3547 – OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3547</guid>
    <pubDate>Mon, 12 Jul 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3547</strong></p>
  <p>OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3613 – OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3613</guid>
    <pubDate>Fri, 02 Jul 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3613</strong></p>
  <p>OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3606 – OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dyn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3606</guid>
    <pubDate>Fri, 02 Jul 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3606</strong></p>
  <p>OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35523 – Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35523</guid>
    <pubDate>Mon, 28 Jun 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35523</strong></p>
  <p>Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36382 – OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an asser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36382</guid>
    <pubDate>Fri, 04 Jun 2021 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36382</strong></p>
  <p>OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15077 – OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15077</guid>
    <pubDate>Fri, 04 Jun 2021 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15077</strong></p>
  <p>OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27518 – All versions of Windscribe VPN for Mac and Windows &lt;= v2.02.10 contain a local p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27518</guid>
    <pubDate>Tue, 04 May 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27518</strong></p>
  <p>All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27519 – Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27519</guid>
    <pubDate>Fri, 30 Apr 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27519</strong></p>
  <p>Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the log and log-append along with log injection to create or append to privileged script files and execute code as root/SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15078 – OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15078</guid>
    <pubDate>Mon, 26 Apr 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15078</strong></p>
  <p>OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15078">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
