OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
The vulnerability results from a lack of proper sanitization (validation and cleansing) of PUSH_REPLY message content transmitted by the server to OpenVPN clients. An attacker who controls the VPN server (e.g., a compromised server or a malicious VPN endpoint) can embed unexpected, arbitrary data in these messages. This data reaches the client-side logs without filtering, which can lead to manipulation or obscuring of the data.
An attacker controlling the server can inject arbitrary data into OpenVPN client logs, which can lead to manipulation of audit records and violation of confidentiality and integrity of log data. The effects include obscuring traces of malicious activity and potential further attacks based on log content.
OpenVPN should be updated to version 2.6.11 or newer. Detailed information is available in the official project announcement at https://community.openvpn.net/openvpn/wiki/CVE-2024-5594. Users of Debian distributions should install patches described in the Debian LTS security announcement.
OpenVPN in all versions before 2.6.11
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NOpenvpn
APPOpenvpn2.6.0 – 2.6.11 (excl.)
Related vulnerabilities
OpenVPN: heap buffer over-read przy parsowaniu adresów IP
OpenVPN dla Windows — ładowanie wtyczek z dowolnego katalogu
Use-after-free w OpenVPN 2.6.0–2.6.6 umożliwiający RCE
OpenVPN: Authentication Bypass przez wtyczki z odroczoną autoryzacją
OpenVPN: cross-protocol scripting przez interfejs zarządzania TCP