CVE-2022-33737
06.07.2022, 16:15
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin passwordEnginsight
Vendor | Product | Version |
---|---|---|
openvpn | openvpn_access_server | 2.10.0 ≤ 𝑥 < 2.11.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-708 - Incorrect Ownership AssignmentThe software assigns an owner to a resource, but the owner is outside of the intended control sphere.
- CWE-532 - Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.