CVE-2022-33738
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
Affected (1)
Products: Openvpn: Openvpn Access Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.11.0 |
Related CWEs
CWE-331
Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.
References (2)
Source: security@openvpn.net
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Timeline
No history available yet.