OpenVPN Connect 3.2.0 for Windows

CPE Details

OpenVPN Connect 3.2.0 for Windows
3.2.0
2021-07-06
15h45 +00:00
2021-07-08
20h16 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:openvpn:connect:3.2.0:*:*:*:*:windows:*:*

Informations

Vendor

openvpn

Product

connect

Version

3.2.0

Target Software

windows

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-7245 2024-02-20 11h08 +00:00 The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable
7.8
High
CVE-2022-3761 2023-10-17 12h10 +00:00 OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentials
5.9
Medium
CVE-2021-3613 2021-07-02 10h33 +00:00 OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).
7.8
High