Skip to main content

Vendor/product archive

openvpn / openvpn_access_server CVEs

Beta · best-effort

21 CVEs tagged to openvpn / openvpn_access_server3 Critical, 8 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2025-3110

Published Jul 8, 2026

OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed beh…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-4234

Published Jul 6, 2022

OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33737

Published Jul 6, 2022

The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36382

Published Jun 4, 2021

OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15077

Published Jun 4, 2021

OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authenticat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15074

Published Jul 14, 2020

OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11462

Published May 4, 2020

An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS stat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8953

Published Feb 13, 2020

OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5868

Published May 26, 2017

CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9104

Published Nov 26, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2692

Published May 13, 2014

Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2229

Published May 5, 2006

OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface,…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3409

Published Nov 2, 2005

OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an erro…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3393

Published Nov 1, 2005

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1