Openvpn 2 vulnerabilities
4 known vulnerabilities affecting openvpn/openvpn_2.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2024-27903CRITICALCVSS 9.8v2.6.9 and earlier2024-07-08
CVE-2024-27903 [CRITICAL] CWE-283 CVE-2024-27903: OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
nvd
CVE-2024-24974HIGHCVSS 7.5v2.6.9 and earlier2024-07-08
CVE-2024-24974 [HIGH] CWE-923 CVE-2024-24974: The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
nvd
CVE-2023-46850CRITICALCVSS 9.8≥ 2.6.0, ≤ 2.6.62023-11-11
CVE-2023-46850 [CRITICAL] CWE-416 CVE-2023-46850: Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buff
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
nvd
CVE-2023-46849HIGHCVSS 7.5≥ 2.6.0, ≤ 2.6.62023-11-11
CVE-2023-46849 [HIGH] CWE-369 CVE-2023-46849: Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an
Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
nvd