Skip to main content

Vendor/product archive

openvpn / connect CVEs

Beta · best-effort

8 CVEs tagged to openvpn / connect1 Critical, 6 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-9560

Published May 26, 2026

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC c…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-8474

Published Jan 6, 2025

OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-7245

Published Feb 20, 2024

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodej…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-7224

Published Jan 8, 2024

OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3761

Published Oct 17, 2023

OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download r…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3613

Published Jul 2, 2021

OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15075

Published Mar 30, 2021

OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9442

Published Feb 28, 2020

OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a m…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1