Vulnerabilidades em Openvpn
37 resultadosAnálise Vexday
OpenVPN apresenta um perfil de risco baixo com apenas 1 vulnerabilidade registrada na base, nenhuma sob exploração ativa conhecida. A fraqueza identificada (CWE-617 - Reachable Assertion) é de severidade moderada e foi divulgada recentemente (últimos 90 dias), demandando monitoramento para patches disponibilizados pelo fornecedor.
CVE-2024-1305CRITICALtap-windows6 driver version 9.26 and earlier does not properly
check the size data of incomming write operations which an attacker can
useEPSS 15.4%CVE-2024-24974HIGHThe interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attackerEPSS 9.8%CVE-2024-27903HIGHOpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitraryEPSS 8.9%CVE-2024-27459HIGHThe interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute aEPSS 8.3%CVE-2025-10680HIGHOpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variableEPSS 7.1%CVE-2023-46850—Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending netEPSS 2.0%CVE-2023-46849HIGHUsing the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero beEPSS 1.2%CVE-2024-5594CRITICALOpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arEPSS 0.8%CVE-2025-2704HIGHOpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting EPSS 0.8%CVE-2023-6247MEDIUMThe PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the applEPSS 0.8%CVE-2024-28882MEDIUMOpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the valiEPSS 0.7%CVE-2025-13086MEDIUMImproper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to openEPSS 0.6%CVE-2024-8474HIGHOpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, EPSS 0.5%CVE-2025-12106CRITICALInsufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IPEPSS 0.5%CVE-2026-12996MEDIUMA use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a deniaEPSS 0.5%CVE-2024-4877HIGHOpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI cEPSS 0.4%CVE-2026-12932HIGHA memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackersEPSS 0.4%CVE-2026-13117MEDIUMAn incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-frEPSS 0.4%CVE-2026-11771HIGHOpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentiEPSS 0.4%CVE-2026-13379MEDIUMThe Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a serEPSS 0.3%