← Back

Openvpn

openvpn

68 CVEs • 10 products

Products (10)

Click to collapse
Toggle
Openvpn
openvpn
Connect
connect
Ovpn Dco Win
ovpn-dco-win
Private Tunnel
private_tunnel
Openvpn Gui
openvpn_gui
Openvpn 3
openvpn_3
Tap Windows6
tap-windows6
Easy Rsa
easy-rsa
Openvpn3linux
openvpn3linux

CVEs (68)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openvpn
1Connect
May 27, 2026
May 26, 2026
9.4 CRITICAL· v4
7.8 HIGH· v3
N/A· v2
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
1Openvpn
1Openvpn
Jan 30, 2026
Dec 3, 2025
4.6 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection res...Show more
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating clientShow less
1Openvpn
1Openvpn
Jan 30, 2026
Dec 3, 2025
1.3 LOW· v4
5.5 MEDIUM· v3
N/A· v2
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of servi...Show more
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.Show less
1Openvpn
1Openvpn
Dec 30, 2025
Dec 1, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
1Openvpn
1Ovpn Dco Win
Aug 21, 2025
Jun 20, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash
1Openvpn
1Openvpn3linux
Jun 12, 2025
May 19, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destina...Show more
The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.Show less
1Openvpn
1Openvpn
Apr 29, 2025
Apr 3, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
1Openvpn
1Openvpn
Oct 23, 2025
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
1Openvpn
1Easy Rsa
Aug 22, 2025
Jan 20, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL 3
1Openvpn
1Ovpn Dco Win
Jun 10, 2025
Jan 15, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
1Openvpn
1Connect
Jun 10, 2025
Jan 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
1Openvpn
1Openvpn
Nov 3, 2025
Jan 6, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
1Openvpn
1Openvpn
Jun 10, 2025
Jul 8, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
1Openvpn
1Tap Windows6
Aug 22, 2025
Jul 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary...Show more
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel spaceShow less
1Openvpn
1Openvpn
Nov 21, 2024
Jul 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive s...Show more
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.Show less
1Openvpn
1Openvpn
Nov 21, 2024
Jul 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
1Openvpn
1Openvpn
Nov 21, 2024
Jul 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
1Openvpn
1Openvpn 3
Aug 21, 2025
Feb 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.
1Openvpn
1Openvpn Gui
May 6, 2025
Feb 21, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to...Show more
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.Show less
1Openvpn
1Connect
Apr 2, 2025
Feb 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS...Show more
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable Show less