CVE-2024-5594
published 2025-01-06CVE-2024-5594: OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.82%
53.4th percentile
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvpn | < openvpn 2.6.3-1+deb12u3 (bookworm) | openvpn 2.6.3-1+deb12u3 (bookworm) |
| openvpn | openvpn | < 2.6.11 | 2.6.11 |
| openvpn | openvpn | >= 0 < 2.5.1-3+deb11u1 | 2.5.1-3+deb11u1 |
| openvpn | openvpn | >= 0 < 2.6.3-1+deb12u3 | 2.6.3-1+deb12u3 |
| openvpn | openvpn | >= 0 < 2.6.11-1 | 2.6.11-1 |
| openvpn | openvpn | >= 0 < 2.6.11-1 | 2.6.11-1 |
| openvpn | openvpn | >= 0 < 2.4.12-0ubuntu0.20.04.2 | 2.4.12-0ubuntu0.20.04.2 |
| openvpn | openvpn | >= 0 < 2.5.9-0ubuntu0.22.04.3 | 2.5.9-0ubuntu0.22.04.3 |
| openvpn | openvpn | >= 0 < 2.6.9-1ubuntu4.1 | 2.6.9-1ubuntu4.1 |
| openvpn | openvpn | >= 0 < 2.3.2-7ubuntu3.2+esm2 | 2.3.2-7ubuntu3.2+esm2 |
| openvpn | openvpn | >= 0 < 2.3.10-1ubuntu2.2+esm2 | 2.3.10-1ubuntu2.2+esm2 |
| openvpn | openvpn | >= 0 < 2.4.4-2ubuntu1.7+esm1 | 2.4.4-2ubuntu1.7+esm1 |
| openvpn | openvpn | >= 2.6.0 < 2.6.11 | 2.6.11 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2025-03-13·CVSS 4.3
[MEDIUM] Siemens SINEMA Remote Connect Server
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Release DateMarch 13, 2025
Alert CodeICSA-25-072-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 7.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Improper Output Neutralization for Logs, Missing Release of Resource after Effecti
Ubuntu
OpenVPN vulnerabilities
vendor_ubuntu·2025-03-11·CVSS 9.8
CVE-2024-5594 [CRITICAL] OpenVPN vulnerabilities
Title: OpenVPN vulnerabilities
Summary: Several security issues were fixed in OpenVPN.
It was discovered that OpenVPN did not perform proper input validation
when generating a TLS key under certain configuration, which could lead to
a buffer overflow. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS. (CVE-2017-12166)
Reynir Björnsson discovered that OpenVPN incorrectly handled certain
control channel messages with nonprintable characters. A remote attacker
could possibly use this issue to cause OpenVPN to consume resources, or
fill up log files with garbage, leading to a denial of service.
(CVE-2024-5594)
Instructions: In general, a standard system update will make all the neces
CISA ICS
Siemens SCALANCE M-800 Family
cisa_ics·2024-11-14
Siemens SCALANCE M-800 Family
ICS Advisory
##
Siemens SCALANCE M-800 Family
Release DateNovember 14, 2024
Alert CodeICSA-24-319-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.6
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE M-800 Family
- Vulnerabilities: Out-of-bounds Read, Missing Encryption of Sensitive Data, Integer Overflow or Wraparou
Ubuntu
OpenVPN vulnerabilities
vendor_ubuntu·2024-07-02·CVSS 4.3
CVE-2024-5594 [MEDIUM] OpenVPN vulnerabilities
Title: OpenVPN vulnerabilities
Summary: Several security issues were fixed in OpenVPN.
Reynir Björnsson discovered that OpenVPN incorrectly handled terminating
client connections. A remote authenticated client could possibly use this
issue to keep the connection active, bypassing certain security policies.
This issue only affected Ubuntu 23.10, and Ubuntu 24.04 LTS.
(CVE-2024-28882)
Reynir Björnsson discovered that OpenVPN incorrectly handled certain
control channel messages with nonprintable characters. A remote attacker
could possibly use this issue to cause OpenVPN to consume resources, or
fill up log files with garbage, leading to a denial of service.
(CVE-2024-5594)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2024-5594: openvpn - OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an att...
vendor_debian·2024·CVSS 9.1
CVE-2024-5594 [CRITICAL] CVE-2024-5594: openvpn - OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an att...
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
Scope: local
bookworm: resolved (fixed in 2.6.3-1+deb12u3)
bullseye: resolved (fixed in 2.5.1-3+deb11u1)
forky: resolved (fixed in 2.6.11-1)
sid: resolved (fixed in 2.6.11-1)
trixie: resolved (fixed in 2.6.11-1)
OSV
openvpn vulnerabilities
osv·2025-03-11·CVSS 9.8
CVE-2017-12166 [CRITICAL] openvpn vulnerabilities
openvpn vulnerabilities
It was discovered that OpenVPN did not perform proper input validation
when generating a TLS key under certain configuration, which could lead to
a buffer overflow. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS. (CVE-2017-12166)
Reynir Björnsson discovered that OpenVPN incorrectly handled certain
control channel messages with nonprintable characters. A remote attacker
could possibly use this issue to cause OpenVPN to consume resources, or
fill up log files with garbage, leading to a denial of service.
(CVE-2024-5594)
OSV
CVE-2024-5594: OpenVPN before 2
osv·2025-01-06·CVSS 9.1
CVE-2024-5594 [CRITICAL] CVE-2024-5594: OpenVPN before 2
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
GHSA
GHSA-f2h8-4w6p-535w: OpenVPN before 2
ghsa_unreviewed·2025-01-06
CVE-2024-5594 [CRITICAL] CWE-1287 GHSA-f2h8-4w6p-535w: OpenVPN before 2
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.
OSV
openvpn vulnerabilities
osv·2024-07-02·CVSS 4.3
CVE-2024-28882 [MEDIUM] openvpn vulnerabilities
openvpn vulnerabilities
Reynir Björnsson discovered that OpenVPN incorrectly handled terminating
client connections. A remote authenticated client could possibly use this
issue to keep the connection active, bypassing certain security policies.
This issue only affected Ubuntu 23.10, and Ubuntu 24.04 LTS.
(CVE-2024-28882)
Reynir Björnsson discovered that OpenVPN incorrectly handled certain
control channel messages with nonprintable characters. A remote attacker
could possibly use this issue to cause OpenVPN to consume resources, or
fill up log files with garbage, leading to a denial of service.
(CVE-2024-5594)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-06
Published