Vulnerabilities > Openvpn > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-17 CVE-2022-3761 Improper Certificate Validation vulnerability in Openvpn Connect
OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentials
network
high complexity
openvpn CWE-295
5.9
2022-07-06 CVE-2021-4234 Unspecified vulnerability in Openvpn Access Server
OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack.
network
low complexity
openvpn
5.0
2022-07-06 CVE-2022-33738 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Openvpn Access Server
OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
network
low complexity
openvpn CWE-338
5.0
2021-09-23 CVE-2021-3824 Cross-site Scripting vulnerability in Openvpn Access Server
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
network
openvpn CWE-79
4.3
2021-07-02 CVE-2021-3606 Uncontrolled Search Path Element vulnerability in Openvpn
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).
4.4
2021-07-02 CVE-2021-3613 Uncontrolled Search Path Element vulnerability in Openvpn Connect
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).
4.4
2021-06-04 CVE-2020-36382 Reachable Assertion vulnerability in Openvpn Access Server
OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.
network
low complexity
openvpn CWE-617
5.0
2020-07-14 CVE-2020-15074 Insufficient Session Expiration vulnerability in Openvpn Access Server
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
network
low complexity
openvpn CWE-613
5.0
2020-05-04 CVE-2020-11462 XML Entity Expansion vulnerability in Openvpn Access Server
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3.
network
openvpn CWE-776
4.3
2018-05-01 CVE-2018-9336 Double Free vulnerability in multiple products
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service.
local
low complexity
openvpn slackware CWE-415
4.6