The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15743 The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Openvpn
Openvpn openvpn3linux
CPEs cpe:2.3:a:openvpn:openvpn3linux:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Openvpn
Openvpn openvpn3linux

Tue, 20 May 2025 18:45:00 +0000

Type Values Removed Values Added
References

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 19 May 2025 15:15:00 +0000

Type Values Removed Values Added
Description The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
Weaknesses CWE-59
References

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2025-05-20T18:04:08.335Z

Reserved: 2025-04-23T17:39:28.844Z

Link: CVE-2025-3908

cve-icon Vulnrichment

Updated: 2025-05-20T18:04:08.335Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-19T15:15:23.860

Modified: 2025-06-12T16:25:23.957

Link: CVE-2025-3908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.