← Back

Openvpn

openvpn

Vendor: Aviatrix • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aviatrix
1Openvpn
Nov 21, 2024
Apr 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
1Aviatrix
1Openvpn
Nov 21, 2024
Apr 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.