CVE-2024-8474
EUVD-2024-4962906.01.2025, 15:15
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN trafficEnginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openvpn | connect | 𝑥 ≤ 3.5.0 | CNA |