Skip to content

Commit

Permalink
OpenVPN Critical Vulnerability - 20250110002 (#1154)
Browse files Browse the repository at this point in the history
  • Loading branch information
Dinindu-Wick authored Jan 10, 2025
1 parent 8a23e6c commit 0586f72
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions docs/advisories/20250110002-OpenVPN-Critical-Vulnerability.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# OpenVPN Critical Vulnerability - 20250110002

## Overview

Security vulnerabilities within OpenVPN, first identified and patched in June 2024, has recently been disclosed publicly (as of January 2025) as being critical in severity. Exploitation of the vulnerability(s) allows attackers to inject arbitrary data into third-party executables or plug-ins, allowing them to execute code or cause denial-of-service attacks.

## What is vulnerable?

| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
| ------------------- | ---------- | ----------------------------------------------------------------------- | ------------ | ------------------- |
| OpenVPN | < 2.6.11 | [CVE-2024-5594](https://nvd.nist.gov/vuln/detail/CVE-2024-5594) | 9.1 | **Critical** |


## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours...* (refer [Patch Management](../guidelines/patch-management.md)):

- OpenVPN: <https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html>

0 comments on commit 0586f72

Please sign in to comment.