The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.05418}

epss

{'score': 0.05558}


Sat, 10 Aug 2024 04:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:openvpn:openvpn_gui:*:*:*:*:*:*:*:*
Vendors & Products Openvpn openvpn Gui
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2024-08-23T15:05:42.997Z

Reserved: 2024-03-12T18:26:01.720Z

Link: CVE-2024-27459

cve-icon Vulnrichment

Updated: 2024-08-02T00:34:52.326Z

cve-icon NVD

Status : Modified

Published: 2024-07-08T11:15:10.303

Modified: 2024-11-21T09:04:39.057

Link: CVE-2024-27459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.