OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://openvpn.net/connect-docs/android-release-notes.html |
History
Mon, 06 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 06 Jan 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic | |
Weaknesses | CWE-212 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: OpenVPN
Published: 2025-01-06T14:33:26.129Z
Updated: 2025-01-06T16:54:38.487Z
Reserved: 2024-09-05T08:38:27.571Z
Link: CVE-2024-8474
Vulnrichment
Updated: 2025-01-06T16:54:33.381Z
NVD
Status : Received
Published: 2025-01-06T15:15:14.983
Modified: 2025-01-06T17:15:44.747
Link: CVE-2024-8474
Redhat
No data.