Vulnerability index

Browse CVEs

71 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openvpn CRITICAL 9.8
CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buff…

Fix: 2.12.2+
Fix from $2,300 2023-11-11
Openvpn HIGH 7.5
CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour w…

Fix: after 2.11.3
Fix from $1,950 2023-11-11
Connect MEDIUM 5.9
CVE-2022-3761

OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept co…

Fix: 3.4.0.3121 / 3.4.0.4506+
Fix from $1,600 2023-10-17
Openvpn HIGH 7.5
CVE-2020-20813

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

Fix: after 2.4.7
Fix from $1,950 2023-08-22
Openvpn Access Server HIGH 7.5
CVE-2021-4234

OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client whic…

Fix: 2.11.0+
Fix from $1,950 2022-07-06
Openvpn Access Server HIGH 7.5
CVE-2022-33737

The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random genera…

Fix: 2.11.0+
Fix from $1,950 2022-07-06
Openvpn Access Server HIGH 7.5
CVE-2022-33738

OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal

Fix: 2.11.0+
Fix from $1,950 2022-07-06
Openvpn CRITICAL 9.8
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of def…

Fix: 2.4.12 / 2.5.6+
Fix from $2,300 2022-03-18
Openvpn Access Server MEDIUM 6.1
CVE-2021-3824

OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.

Fix: after 2.9.4
Fix from $1,600 2021-09-23
Openvpn HIGH 7.4
CVE-2021-3547

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated ser…

Patch available
Fix from $1,950 2021-07-12
Connect HIGH 7.8
CVE-2021-3613

OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, whi…

Fix: after 3.3.0
Fix from $1,950 2021-07-02
Openvpn HIGH 7.8
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present,…

Fix: 2.5.3+
Fix from $1,950 2021-07-02
Openvpn Access Server HIGH 7.5
CVE-2020-36382

OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication t…

Fix: after 2.8.7
Fix from $1,950 2021-06-04
Openvpn Access Server MEDIUM 5.3
CVE-2020-15077

OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers config…

Fix: after 2.8.7
Fix from $1,600 2021-06-04
Private Tunnel HIGH 7.8
CVE-2020-15076

Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp.

Fix: after 3.0.1
Fix from $1,950 2021-05-26
Openvpn HIGH 7.5
CVE-2020-15078

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with defe…

Fix: 2.4.11 / 2.5.2+
Fix from $1,950 2021-04-26
Connect HIGH 7.1
CVE-2020-15075

OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.

Fix: after 3.2.6
Fix from $1,950 2021-03-30
Openvpn Access Server HIGH 7.5
CVE-2020-15074

OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconn…

Fix: 2.8.4 / 2.9.6+
Fix from $1,950 2020-07-14
Openvpn Access Server HIGH 7.5
CVE-2020-11462

An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible t…

Fix: 2.7.0+
Fix from $1,950 2020-05-04
Connect HIGH 7.8
CVE-2020-9442

OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to …

Fix: after 3.1.0.361
Fix from $1,950 2020-02-28
Openvpn Access Server CRITICAL 9.8
CVE-2020-8953

OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

Fix: 2.8.1+
Fix from $2,300 2020-02-13
Openvpn HIGH 7.8
CVE-2018-9336

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sendin…

Fix: 2.4.6+
Fix from $1,950 2018-05-01
Openvpn CRITICAL 9.1
CVE-2018-7544

A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without…

Fix: after 2.4.5
Fix from $2,300 2018-03-16
Openvpn CRITICAL 9.8
CVE-2017-12166

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting …

Fix: 2.3.18 / 2.4.4+
Fix from $2,300 2017-10-04
Openvpn HIGH 7.5
CVE-2017-7508

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.

Fix: after 2.3.16
Fix from $1,950 2017-06-27
Openvpn HIGH 7.4
CVE-2017-7520

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-mid…

Fix: after 2.3.16
Fix from $1,950 2017-06-27
Openvpn MEDIUM 6.5
CVE-2017-7522EPSS 6%

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with a…

Fix: after 2.3.16
Fix from $1,600 2017-06-27
Openvpn MEDIUM 5.9
CVE-2017-7521

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double…

Fix: after 2.3.16
Fix from $1,600 2017-06-27
Openvpn Access Server MEDIUM 6.1
CVE-2017-5868

CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequ…

No fix yet
Fix from $1,600 2017-05-26
Openvpn HIGH 7.5
CVE-2017-7478EPSS 14%

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue…

No fix yet
Fix from $1,950 2017-05-15