Записи OpenVPN
79 опубликованных записей вендора openvpn.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 55,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-617 Reachable Assertion5
- CWE-305 Authentication Bypass by Primary Weakness4
- CWE-125 Out-of-bounds Read3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
79 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2024-1305Эксплойта нет | tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can useopenvpn · tap-windows6 · CWE-190 | Критическая9,8 | — | 15,4 % | 8 июл. 2024 г. |
42В плане | CVE-2024-27903Эксплойта нет | OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitraryopenvpn · openvpn · CWE-283 | Критическая9,8 | — | 8,9 % | 8 июл. 2024 г. |
40В плане | CVE-2017-12166Эксплойта нет | OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly ropenvpn · openvpn · CWE-787 | Критическая9,8 | — | 3,6 % | 3 окт. 2017 г. |
40В плане | CVE-2022-0547Эксплойта нет | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes uopenvpn · openvpn · CWE-305 | Критическая9,8 | — | 3,6 % | 18 мар. 2022 г. |
40В плане | CVE-2023-46850Эксплойта нет | Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending netopenvpn · openvpn · CWE-416 | Критическая9,8 | — | 2,0 % | 10 нояб. 2023 г. |
39Наблюдать | CVE-2020-8953Эксплойта нет | OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).openvpn · openvpn access server · CWE-287 | Критическая9,8 | — | 1,3 % | 13 февр. 2020 г. |
37Наблюдать | CVE-2006-1629Эксплойта нет | OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD enviroopenvpn · openvpn | Критическая9,0 | — | 3,1 % | 6 апр. 2006 г. |
37Наблюдать | CVE-2018-7544Эксплойта нет | A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5.openvpn · openvpn · CWE-134 | Критическая9,1 | — | 1,8 % | 16 мар. 2018 г. |
37Наблюдать | CVE-2026-9560Proof of concept | Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands wopenvpn · connect · CWE-78 | Критическая9,4 | — | 0,4 % | 26 мая 2026 г. |
36Наблюдать | CVE-2024-5594Эксплойта нет | OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected aropenvpn · openvpn · CWE-1287 | Критическая9,1 | — | 0,8 % | 6 янв. 2025 г. |
36Наблюдать | CVE-2025-12106Эксплойта нет | Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IPopenvpn · openvpn · CWE-126 | Критическая9,1 | — | 0,6 % | 1 дек. 2025 г. |
35Наблюдать | CVE-2024-4877Эксплойта нет | OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI copenvpn · openvpn · CWE-268 | Высокая8,8 | — | 0,4 % | 3 апр. 2025 г. |
34Наблюдать | CVE-2017-7478Proof of concept | OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.openvpn · openvpn · CWE-617 | Высокая7,5 | — | 13,8 % | 15 мая 2017 г. |
33Наблюдать | CVE-2024-24974Эксплойта нет | The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attackeropenvpn · openvpn · CWE-923 | Высокая7,5 | — | 9,8 % | 8 июл. 2024 г. |
33Наблюдать | CVE-2024-27459Эксплойта нет | The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute aopenvpn · openvpn · CWE-121 | Высокая7,8 | — | 8,3 % | 8 июл. 2024 г. |
33Наблюдать | CVE-2023-7235Эксплойта нет | The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN bopenvpn · openvpn gui · CWE-276 | Высокая8,4 | — | 0,2 % | 21 февр. 2024 г. |
31Наблюдать | CVE-2020-15078Эксплойта нет | OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured openvpn · openvpn · CWE-305 | Высокая7,5 | — | 4,9 % | 26 апр. 2021 г. |
31Наблюдать | CVE-2017-7508Эксплойта нет | OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.openvpn · openvpn · CWE-617 | Высокая7,5 | — | 4,8 % | 27 июн. 2017 г. |
31Наблюдать | CVE-2005-3393Эксплойта нет | Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code viopenvpn · openvpn | Высокая7,5 | — | 3,5 % | 1 нояб. 2005 г. |
31Наблюдать | CVE-2008-3459Эксплойта нет | Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitopenvpn · openvpn · CWE-16 | Высокая7,6 | — | 2,1 % | 4 авг. 2008 г. |
31Наблюдать | CVE-2020-36382Эксплойта нет | OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentopenvpn · openvpn access server · CWE-754 | Высокая7,5 | — | 1,9 % | 4 июн. 2021 г. |
31Наблюдать | CVE-2021-3613Эксплойта нет | OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if preopenvpn · connect · CWE-427 | Высокая7,8 | — | 0,8 % | 2 июл. 2021 г. |
31Наблюдать | CVE-2020-9442Proof of concept | OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local openvpn · connect · CWE-281 | Высокая7,8 | — | 0,6 % | 28 февр. 2020 г. |
31Наблюдать | CVE-2018-9336Эксплойта нет | openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory openvpn · openvpn · CWE-415 | Высокая7,8 | — | 0,6 % | 1 мая 2018 г. |
31Наблюдать | CVE-2020-15076Эксплойта нет | Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinksopenvpn · private tunnel · CWE-61 | Высокая7,8 | — | 0,4 % | 26 мая 2021 г. |
- CVE-2024-130544В плане
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %openvpn · tap-windows68 июл. 2024 г.
- CVE-2024-2790342В плане
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %openvpn · openvpn8 июл. 2024 г.
- CVE-2017-1216640В плане
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly r
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %openvpn · openvpn3 окт. 2017 г.
- CVE-2022-054740В плане
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes u
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %openvpn · openvpn18 мар. 2022 г.
- CVE-2023-4685040В плане
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending net
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openvpn · openvpn10 нояб. 2023 г.
- CVE-2020-895339Наблюдать
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openvpn · openvpn access server13 февр. 2020 г.
- CVE-2006-162937Наблюдать
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD enviro
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %openvpn · openvpn6 апр. 2006 г.
- CVE-2018-754437Наблюдать
A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %openvpn · openvpn16 мар. 2018 г.
- CVE-2026-956037Наблюдать
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands w
КритическаяCVSS 9,4Proof of conceptEPSS 0 %openvpn · connect26 мая 2026 г.
- CVE-2024-559436Наблюдать
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected ar
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %openvpn · openvpn6 янв. 2025 г.
- CVE-2025-1210636Наблюдать
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %openvpn · openvpn1 дек. 2025 г.
- CVE-2024-487735Наблюдать
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI c
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %openvpn · openvpn3 апр. 2025 г.
- CVE-2017-747834Наблюдать
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %openvpn · openvpn15 мая 2017 г.
- CVE-2024-2497433Наблюдать
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %openvpn · openvpn8 июл. 2024 г.
- CVE-2024-2745933Наблюдать
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute a
ВысокаяCVSS 7,8Эксплойта нетEPSS 8 %openvpn · openvpn8 июл. 2024 г.
- CVE-2023-723533Наблюдать
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN b
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %openvpn · openvpn gui21 февр. 2024 г.
- CVE-2020-1507831Наблюдать
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %openvpn · openvpn26 апр. 2021 г.
- CVE-2017-750831Наблюдать
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %openvpn · openvpn27 июн. 2017 г.
- CVE-2005-339331Наблюдать
Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openvpn · openvpn1 нояб. 2005 г.
- CVE-2008-345931Наблюдать
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbit
ВысокаяCVSS 7,6Эксплойта нетEPSS 2 %openvpn · openvpn4 авг. 2008 г.
- CVE-2020-3638231Наблюдать
OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authent
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openvpn · openvpn access server4 июн. 2021 г.
- CVE-2021-361331Наблюдать
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if pre
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %openvpn · connect2 июл. 2021 г.
- CVE-2020-944231Наблюдать
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %openvpn · connect28 февр. 2020 г.
- CVE-2018-933631Наблюдать
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %openvpn · openvpn1 мая 2018 г.
- CVE-2020-1507631Наблюдать
Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %openvpn · private tunnel26 мая 2021 г.