Vulnerabilidades en Openvpn

37 resultados
Análisis Vexday

OpenVPN apresenta um perfil de risco baixo com apenas 1 vulnerabilidade registrada na base, nenhuma sob exploração ativa conhecida. A fraqueza identificada (CWE-617 - Reachable Assertion) é de severidade moderada e foi divulgada recentemente (últimos 90 dias), demandando monitoramento para patches disponibilizados pelo fornecedor.

CVE-2026-35058MEDIUMImproper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows EPSS 0.3%CVE-2026-40215MEDIUMA race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash orEPSS 0.3%CVE-2025-15497LOWInsufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resultinEPSS 0.3%CVE-2023-7245HIGHThe nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to EPSS 0.3%CVE-2026-13698MEDIUMA memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valiEPSS 0.3%CVE-2026-13122MEDIUMOpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed autheEPSS 0.3%CVE-2025-3110MEDIUMOpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HEPSS 0.3%CVE-2023-7224HIGHOpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSEREPSS 0.2%CVE-2025-50054MEDIUMBuffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too laEPSS 0.2%CVE-2023-7235HIGHThe OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN bEPSS 0.2%CVE-2025-50055MEDIUMCross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows conEPSS 0.2%CVE-2025-3908MEDIUMThe configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbEPSS 0.2%CVE-2025-13751LOWInteractive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated useEPSS 0.2%CVE-2026-11604MEDIUMAn incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authentiEPSS 0.1%CVE-2024-5198LOWOpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driveEPSS 0.1%CVE-2026-2738MEDIUMBuffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peerEPSS 0.1%CVE-2024-13454MEDIUMWeak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when EPSS 0.1%