CVE-2022-33737: High severity openvpn access server vulnerability
Published Jul 6, 2022
·Updated
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
Affected Software
1 affected component
OpenVPN OpenVPN Access Server>=2.10.0<2.11.0
Event History
Jul 6, 2022
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-33737.
2
What is the severity of CVE-2022-33737?
The severity of CVE-2022-33737 is high.
3
What does the OpenVPN Access Server installer do that creates the vulnerability?
The OpenVPN Access Server installer creates a log file readable for everyone, which may contain a random generated admin password.
4
Which versions of the OpenVPN Access Server are affected?
Versions 2.10.0 and previous versions before 2.11.0 of the OpenVPN Access Server are affected.
5
How can I fix CVE-2022-33737?
To fix CVE-2022-33737, it is recommended to update to version 2.11.0 or later of the OpenVPN Access Server.