Insecure Communication Affecting openvpn package, versions [,2.5.10) [2.6.0,2.6.10)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.06% (30th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-OPENVPN-7689065
- published 16 Aug 2024
- disclosed 8 Jul 2024
- credit Vladimir Tokarev
Introduced: 8 Jul 2024
CVE-2024-24974 Open this link in a new tabHow to fix?
Upgrade openvpn
to version 2.5.10, 2.6.10 or higher.
Overview
Affected versions of this package are vulnerable to Insecure Communication through the interactive service. An attacker can gain unauthorized access and interact with the privileged OpenVPN interactive service by exploiting the remote accessibility of the OpenVPN service pipe.
Note:
When chained with CVE-2024-27903, it could result in remote code execution.