CVE-2024-27903
EUVD-2024-2509508.07.2024, 11:15
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openvpn | openvpn | 𝑥 < 2.5.10 |
| openvpn | openvpn | 2.6.0 ≤ 𝑥 < 2.6.10 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openvpn | openvpn2 | 𝑥 < 2.6.10 | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
- CWE-283 - Unverified OwnershipThe software does not properly verify that a critical resource is owned by the proper entity.
- CWE-434 - Unrestricted Upload of File with Dangerous TypeThe software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
References