OpenVPN kayıtları
openvpn üreticisine ait 79 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %55,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-617 Reachable Assertion5
- CWE-305 Authentication Bypass by Primary Weakness4
- CWE-125 Out-of-bounds Read3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
79 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2024-1305İstismar yok | tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can useopenvpn · tap-windows6 · CWE-190 | Kritik9,8 | — | %15,4 | 8 Tem 2024 |
42Planlayın | CVE-2024-27903İstismar yok | OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitraryopenvpn · openvpn · CWE-283 | Kritik9,8 | — | %8,9 | 8 Tem 2024 |
40Planlayın | CVE-2017-12166İstismar yok | OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly ropenvpn · openvpn · CWE-787 | Kritik9,8 | — | %3,6 | 3 Eki 2017 |
40Planlayın | CVE-2022-0547İstismar yok | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes uopenvpn · openvpn · CWE-305 | Kritik9,8 | — | %3,6 | 18 Mar 2022 |
40Planlayın | CVE-2023-46850İstismar yok | Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending netopenvpn · openvpn · CWE-416 | Kritik9,8 | — | %2,0 | 10 Kas 2023 |
39İzleyin | CVE-2020-8953İstismar yok | OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).openvpn · openvpn access server · CWE-287 | Kritik9,8 | — | %1,3 | 13 Şub 2020 |
37İzleyin | CVE-2006-1629İstismar yok | OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD enviroopenvpn · openvpn | Kritik9,0 | — | %3,1 | 6 Nis 2006 |
37İzleyin | CVE-2018-7544İstismar yok | A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5.openvpn · openvpn · CWE-134 | Kritik9,1 | — | %1,8 | 16 Mar 2018 |
37İzleyin | CVE-2026-9560Kavram kanıtı | Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands wopenvpn · connect · CWE-78 | Kritik9,4 | — | %0,4 | 26 May 2026 |
36İzleyin | CVE-2024-5594İstismar yok | OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected aropenvpn · openvpn · CWE-1287 | Kritik9,1 | — | %0,8 | 6 Oca 2025 |
36İzleyin | CVE-2025-12106İstismar yok | Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IPopenvpn · openvpn · CWE-126 | Kritik9,1 | — | %0,6 | 1 Ara 2025 |
35İzleyin | CVE-2024-4877İstismar yok | OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI copenvpn · openvpn · CWE-268 | Yüksek8,8 | — | %0,4 | 3 Nis 2025 |
34İzleyin | CVE-2017-7478Kavram kanıtı | OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.openvpn · openvpn · CWE-617 | Yüksek7,5 | — | %13,8 | 15 May 2017 |
33İzleyin | CVE-2024-24974İstismar yok | The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attackeropenvpn · openvpn · CWE-923 | Yüksek7,5 | — | %9,8 | 8 Tem 2024 |
33İzleyin | CVE-2024-27459İstismar yok | The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute aopenvpn · openvpn · CWE-121 | Yüksek7,8 | — | %8,3 | 8 Tem 2024 |
33İzleyin | CVE-2023-7235İstismar yok | The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN bopenvpn · openvpn gui · CWE-276 | Yüksek8,4 | — | %0,2 | 21 Şub 2024 |
31İzleyin | CVE-2020-15078İstismar yok | OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured openvpn · openvpn · CWE-305 | Yüksek7,5 | — | %4,9 | 26 Nis 2021 |
31İzleyin | CVE-2017-7508İstismar yok | OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.openvpn · openvpn · CWE-617 | Yüksek7,5 | — | %4,8 | 27 Haz 2017 |
31İzleyin | CVE-2005-3393İstismar yok | Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code viopenvpn · openvpn | Yüksek7,5 | — | %3,5 | 1 Kas 2005 |
31İzleyin | CVE-2008-3459İstismar yok | Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitopenvpn · openvpn · CWE-16 | Yüksek7,6 | — | %2,1 | 4 Ağu 2008 |
31İzleyin | CVE-2020-36382İstismar yok | OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentopenvpn · openvpn access server · CWE-754 | Yüksek7,5 | — | %1,9 | 4 Haz 2021 |
31İzleyin | CVE-2021-3613İstismar yok | OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if preopenvpn · connect · CWE-427 | Yüksek7,8 | — | %0,8 | 2 Tem 2021 |
31İzleyin | CVE-2020-9442Kavram kanıtı | OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local openvpn · connect · CWE-281 | Yüksek7,8 | — | %0,6 | 28 Şub 2020 |
31İzleyin | CVE-2018-9336İstismar yok | openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory openvpn · openvpn · CWE-415 | Yüksek7,8 | — | %0,6 | 1 May 2018 |
31İzleyin | CVE-2020-15076İstismar yok | Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinksopenvpn · private tunnel · CWE-61 | Yüksek7,8 | — | %0,4 | 26 May 2021 |
- CVE-2024-130544Planlayın
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use
KritikCVSS 9,8İstismar yokEPSS %15openvpn · tap-windows68 Tem 2024
- CVE-2024-2790342Planlayın
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary
KritikCVSS 9,8İstismar yokEPSS %9openvpn · openvpn8 Tem 2024
- CVE-2017-1216640Planlayın
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly r
KritikCVSS 9,8İstismar yokEPSS %4openvpn · openvpn3 Eki 2017
- CVE-2022-054740Planlayın
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes u
KritikCVSS 9,8İstismar yokEPSS %4openvpn · openvpn18 Mar 2022
- CVE-2023-4685040Planlayın
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending net
KritikCVSS 9,8İstismar yokEPSS %2openvpn · openvpn10 Kas 2023
- CVE-2020-895339İzleyin
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
KritikCVSS 9,8İstismar yokEPSS %1openvpn · openvpn access server13 Şub 2020
- CVE-2006-162937İzleyin
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD enviro
KritikCVSS 9,0İstismar yokEPSS %3openvpn · openvpn6 Nis 2006
- CVE-2018-754437İzleyin
A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5.
KritikCVSS 9,1İstismar yokEPSS %2openvpn · openvpn16 Mar 2018
- CVE-2026-956037İzleyin
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands w
KritikCVSS 9,4Kavram kanıtıEPSS %0openvpn · connect26 May 2026
- CVE-2024-559436İzleyin
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected ar
KritikCVSS 9,1İstismar yokEPSS %1openvpn · openvpn6 Oca 2025
- CVE-2025-1210636İzleyin
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP
KritikCVSS 9,1İstismar yokEPSS %1openvpn · openvpn1 Ara 2025
- CVE-2024-487735İzleyin
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI c
YüksekCVSS 8,8İstismar yokEPSS %0openvpn · openvpn3 Nis 2025
- CVE-2017-747834İzleyin
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.
YüksekCVSS 7,5Kavram kanıtıEPSS %14openvpn · openvpn15 May 2017
- CVE-2024-2497433İzleyin
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker
YüksekCVSS 7,5İstismar yokEPSS %10openvpn · openvpn8 Tem 2024
- CVE-2024-2745933İzleyin
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute a
YüksekCVSS 7,8İstismar yokEPSS %8openvpn · openvpn8 Tem 2024
- CVE-2023-723533İzleyin
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN b
YüksekCVSS 8,4İstismar yokEPSS %0openvpn · openvpn gui21 Şub 2024
- CVE-2020-1507831İzleyin
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured
YüksekCVSS 7,5İstismar yokEPSS %5openvpn · openvpn26 Nis 2021
- CVE-2017-750831İzleyin
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.
YüksekCVSS 7,5İstismar yokEPSS %5openvpn · openvpn27 Haz 2017
- CVE-2005-339331İzleyin
Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code vi
YüksekCVSS 7,5İstismar yokEPSS %3openvpn · openvpn1 Kas 2005
- CVE-2008-345931İzleyin
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbit
YüksekCVSS 7,6İstismar yokEPSS %2openvpn · openvpn4 Ağu 2008
- CVE-2020-3638231İzleyin
OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authent
YüksekCVSS 7,5İstismar yokEPSS %2openvpn · openvpn access server4 Haz 2021
- CVE-2021-361331İzleyin
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if pre
YüksekCVSS 7,8İstismar yokEPSS %1openvpn · connect2 Tem 2021
- CVE-2020-944231İzleyin
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local
YüksekCVSS 7,8Kavram kanıtıEPSS %1openvpn · connect28 Şub 2020
- CVE-2018-933631İzleyin
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory
YüksekCVSS 7,8İstismar yokEPSS %1openvpn · openvpn1 May 2018
- CVE-2020-1507631İzleyin
Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks
YüksekCVSS 7,8İstismar yokEPSS %0openvpn · private tunnel26 May 2021