CVE-2024-8474
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-8474 is a vulnerability affecting OpenVPN Connect versions prior to 3.5.0. This issue arises due to the application logging the clear-text private key contained within the configuration profile. An unauthorized actor who gains access to these logs can decrypt VPN traffic, potentially compromising sensitive information exchanged over the VPN connection. To mitigate this risk, it is recommended that users update OpenVPN Connect to the latest version as soon as possible. Additionally, securing the logs and restricting access to them can help prevent unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Openvpn Connect
Affected Vendors
- OpenVPN Inc.