The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 02 Apr 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openvpn
Openvpn connect |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:openvpn:connect:*:*:*:*:*:macos:*:* cpe:2.3:a:openvpn:connect:*:*:*:*:*:windows:*:* cpe:2.3:a:openvpn:connect:3.0.0:beta:*:*:*:macos:*:* cpe:2.3:a:openvpn:connect:3.0.0:beta:*:*:*:windows:*:* cpe:2.3:a:openvpn:connect:3.0.1:beta:*:*:*:macos:*:* cpe:2.3:a:openvpn:connect:3.0.2:beta:*:*:*:macos:*:* cpe:2.3:a:openvpn:connect:3.1.0:beta:*:*:*:macos:*:* cpe:2.3:a:openvpn:connect:3.1.0:beta:*:*:*:windows:*:* cpe:2.3:a:openvpn:connect:3.1.1:beta:*:*:*:macos:*:* cpe:2.3:a:openvpn:connect:3.1.1:beta:*:*:*:windows:*:* cpe:2.3:a:openvpn:connect:3.1.2:beta:*:*:*:windows:*:* cpe:2.3:a:openvpn:connect:3.1.3:beta:*:*:*:windows:*:* |
|
| Vendors & Products |
Openvpn
Openvpn connect |
Wed, 14 Aug 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2024-08-14T14:36:15.335Z
Reserved: 2024-02-07T13:25:05.853Z
Link: CVE-2023-7245
Updated: 2024-08-02T08:57:35.027Z
Status : Analyzed
Published: 2024-02-20T11:15:07.750
Modified: 2025-04-02T20:11:54.737
Link: CVE-2023-7245
No data.
OpenCVE Enrichment
No data.
Weaknesses