Show filters
87 Total Results
Displaying 1-10 of 87
Sort by:
Attacker Value
Moderate
CVE-2019-17387
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
0
Attacker Value
High
CVE-2019-17388
Disclosure Date: March 28, 2019 (last updated November 27, 2024)
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
0
Attacker Value
Unknown
CVE-2024-3661
Disclosure Date: May 06, 2024 (last updated January 16, 2025)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
0
Attacker Value
Unknown
CVE-2023-5748
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2023-47101
Disclosure Date: October 30, 2023 (last updated November 08, 2023)
The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair.
0
Attacker Value
Unknown
CVE-2022-46783
Disclosure Date: August 28, 2023 (last updated October 08, 2023)
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.
0
Attacker Value
Unknown
CVE-2021-27932
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
0
Attacker Value
Unknown
CVE-2022-46782
Disclosure Date: August 05, 2023 (last updated October 08, 2023)
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine.
0
Attacker Value
Unknown
CVE-2021-27406
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This could result in the attacker achieving execution with privileges of a SYSTEM user.
0
Attacker Value
Unknown
CVE-2021-20051
Disclosure Date: May 04, 2022 (last updated October 07, 2023)
SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system.
0