CVE-2023-7235: High severity openvpn openvpn gui vulnerability
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7235?
CVE-2023-7235 is classified as a medium severity vulnerability due to its potential to allow unauthorized binary replacement.
How do I fix CVE-2023-7235?
To fix CVE-2023-7235, you should update the OpenVPN GUI to version 2.6.9 or later to ensure proper access control is enforced.
What versions of OpenVPN GUI are affected by CVE-2023-7235?
CVE-2023-7235 affects OpenVPN GUI installations prior to version 2.6.9.
What impact does CVE-2023-7235 have on system security?
CVE-2023-7235 can allow an attacker to replace binaries, potentially leading to arbitrary code execution on the affected system.
Is there a way to mitigate CVE-2023-7235 if I cannot update immediately?
If immediate updating is not possible, ensure that the installation directory has restricted access to prevent unauthorized users from modifying binaries.