CVE-2020-7224: Critical severity aviatrix openvpn vulnerability
Published Apr 16, 2020
·Updated
The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.
Affected Software
1 affected component
Aviatrix OpenVPN<=2.5.7
Event History
Apr 16, 2020
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Aviatrix OpenVPN client vulnerability?
The vulnerability ID for this Aviatrix OpenVPN client vulnerability is CVE-2020-7224.
2
What is the severity of CVE-2020-7224?
CVE-2020-7224 has a severity rating of 9.8 (critical).
3
Which operating systems are affected by CVE-2020-7224?
CVE-2020-7224 affects Linux, macOS, and Windows operating systems.
4
How can unauthorized third-party libraries load due to this vulnerability?
Unauthorized third-party libraries can load due to altered OpenSSL parameters from the issued value set.
5
How can I fix CVE-2020-7224?
To fix CVE-2020-7224, update the Aviatrix OpenVPN client to version 2.5.7 or later.