The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.
History

Mon, 26 Aug 2024 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published: 2024-02-21T10:55:15.487Z

Updated: 2024-08-26T16:13:36.611Z

Reserved: 2024-01-16T15:21:16.217Z

Link: CVE-2023-7235

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.194Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-21T11:15:07.673

Modified: 2024-08-26T17:35:02.810

Link: CVE-2023-7235

cve-icon Redhat

No data.