The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.09711}

epss

{'score': 0.09949}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2024-08-10T03:55:21.896Z

Reserved: 2024-03-12T18:26:01.713Z

Link: CVE-2024-24974

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.292Z

cve-icon NVD

Status : Modified

Published: 2024-07-08T11:15:10.103

Modified: 2024-11-21T09:00:04.127

Link: CVE-2024-24974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.