Show filters
63 Total Results
Displaying 21-30 of 63
Sort by:
Attacker Value
Unknown
CVE-2022-33738
Disclosure Date: July 06, 2022 (last updated October 07, 2023)
OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
0
Attacker Value
Unknown
CVE-2022-33737
Disclosure Date: July 06, 2022 (last updated October 07, 2023)
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
0
Attacker Value
Unknown
CVE-2022-0547
Disclosure Date: March 18, 2022 (last updated October 07, 2023)
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
0
Attacker Value
Unknown
CVE-2021-31606
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
0
Attacker Value
Unknown
CVE-2021-31605
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
0
Attacker Value
Unknown
CVE-2021-31604
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
0
Attacker Value
Unknown
CVE-2021-3824
Disclosure Date: September 23, 2021 (last updated February 23, 2025)
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
0
Attacker Value
Unknown
CVE-2021-3547
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.
0
Attacker Value
Unknown
CVE-2021-3613
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).
0
Attacker Value
Unknown
CVE-2021-3606
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).
0