CVE-2024-5594: Critical severity debian/openvpn vulnerability
Last updated 9 April 2025
Other sources
OpenVPN before 2.6.11 does not santize PUSHREPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5594?
CVE-2024-5594 is considered a high-severity vulnerability due to its potential for arbitrary code execution through improper sanitation of PUSH_REPLY messages.
How do I fix CVE-2024-5594?
To fix CVE-2024-5594, upgrade your OpenVPN version to at least 2.6.12-1 to ensure proper sanitization of PUSH_REPLY messages.
Which OpenVPN versions are affected by CVE-2024-5594?
OpenVPN versions before 2.6.11, including versions up to 2.5.1-3 and 2.6.3-1+deb12u2, are affected by CVE-2024-5594.
What are the potential impacts of CVE-2024-5594 if exploited?
Exploitation of CVE-2024-5594 could allow attackers to inject unexpected and potentially malicious data into third-party executables or plug-ins.
Are there any known exploits for CVE-2024-5594?
As of now, no public exploits for CVE-2024-5594 have been widely reported, but the vulnerability poses a significant risk given its characteristics.