CVE-2024-8474

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 6, 2025
CWE ID 212

Summary

CVE-2024-8474 is a vulnerability affecting OpenVPN Connect versions prior to 3.5.0. This issue arises due to the application logging the clear-text private key contained within the configuration profile. An unauthorized actor who gains access to these logs can decrypt VPN traffic, potentially compromising sensitive information exchanged over the VPN connection. To mitigate this risk, it is recommended that users update OpenVPN Connect to the latest version as soon as possible. Additionally, securing the logs and restricting access to them can help prevent unauthorized access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Openvpn Connect

Affected Vendors

  • OpenVPN Inc.