cbcvebase.
CVE-2008-3459
published 2008-08-04

CVE-2008-3459: Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via…

PriorityP342high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
2.12%
79.8th percentile
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianopenvpn< openvpn 2.1~rc9-1 (bookworm)openvpn 2.1~rc9-1 (bookworm)
openvpnopenvpn
openvpnopenvpn>= 0 < 2.1~rc9-12.1~rc9-1
openvpnopenvpn>= 0 < 2.1~rc9-12.1~rc9-1
openvpnopenvpn>= 0 < 2.1~rc9-12.1~rc9-1
openvpnopenvpn>= 0 < 2.1~rc9-12.1~rc9-1

CVSS provenance

nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6LOW
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.