CVE-2021-31605: OS Command Injection
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
Other sources
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal SIGTERM.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31605?
CVE-2021-31605 is considered a high severity vulnerability due to its potential to allow command injection.
How do I fix CVE-2021-31605?
To mitigate CVE-2021-31605, upgrade to a version of openvpn-monitor that is greater than 1.1.3.
What systems are affected by CVE-2021-31605?
CVE-2021-31605 affects openvpn-monitor versions up to and including 1.1.3.
What type of vulnerability is CVE-2021-31605?
CVE-2021-31605 is classified as a command injection vulnerability.
What can an attacker do with CVE-2021-31605?
An attacker exploiting CVE-2021-31605 can potentially shut down the OpenVPN server using the SIGTERM signal.