Show filters
63 Total Results
Displaying 21-30 of 63
Sort by:
Attacker Value
Unknown

CVE-2022-33738

Disclosure Date: July 06, 2022 (last updated October 07, 2023)
OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
Attacker Value
Unknown

CVE-2022-33737

Disclosure Date: July 06, 2022 (last updated October 07, 2023)
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
Attacker Value
Unknown

CVE-2022-0547

Disclosure Date: March 18, 2022 (last updated October 07, 2023)
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
Attacker Value
Unknown

CVE-2021-31606

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
Attacker Value
Unknown

CVE-2021-31605

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
Attacker Value
Unknown

CVE-2021-31604

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
Attacker Value
Unknown

CVE-2021-3824

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
Attacker Value
Unknown

CVE-2021-3547

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.
Attacker Value
Unknown

CVE-2021-3613

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).
Attacker Value
Unknown

CVE-2021-3606

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).