First published: Mon Jul 08 2024(Updated: )
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
Credit: security@openvpn.net
Affected Software | Affected Version | How to fix |
---|---|---|
OpenVPN Monitor | <2.5.10 | |
OpenVPN Monitor | >=2.6.0<2.6.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24974 is considered a critical vulnerability due to its potential for remote exploitation.
CVE-2024-24974 affects OpenVPN versions 2.6.9 and earlier, as well as those in the range of 2.6.0 to 2.6.10.
To resolve CVE-2024-24974, upgrade your OpenVPN installation to version 2.6.10 or later.
CVE-2024-24974 allows a remote attacker to interact with the privileged OpenVPN interactive service.
As of now, there are no official workarounds for CVE-2024-24974; upgrading is recommended.