CVE-2024-24974Improper Restriction of Communication Channel to Intended Endpoints in Openvpn

Severity
7.5HIGHNVD
EPSS
11.1%
top 6.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8
Latest updateMar 13

Description

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDopenvpn/openvpn2.6.02.6.10+1
CVEListV5openvpn/openvpn_22.6.9 and earlier

🔴Vulnerability Details

1
GHSA
GHSA-mfqw-44wg-mrpf: The interactive service in OpenVPN 22024-07-08

📋Vendor Advisories

2
CISA ICS
Siemens SINEMA Remote Connect Client2025-03-13
Debian
CVE-2024-24974: openvpn - The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service ...2024

🕵️Threat Intelligence

1
Microsoft
Chained for attack: OpenVPN vulnerabilities discovered leading to RCE and LPE2024-08-08