CRITICAL🇵🇱 Wersja polska

CVE-2024-5594

CVSS 9.1v3.1pub. 2025-01-06upd. 2025-11-03

OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.

🤖 AI Analysis
How it works

The vulnerability results from a lack of proper sanitization (validation and cleansing) of PUSH_REPLY message content transmitted by the server to OpenVPN clients. An attacker who controls the VPN server (e.g., a compromised server or a malicious VPN endpoint) can embed unexpected, arbitrary data in these messages. This data reaches the client-side logs without filtering, which can lead to manipulation or obscuring of the data.

Impact

An attacker controlling the server can inject arbitrary data into OpenVPN client logs, which can lead to manipulation of audit records and violation of confidentiality and integrity of log data. The effects include obscuring traces of malicious activity and potential further attacks based on log content.

Mitigation & patch

OpenVPN should be updated to version 2.6.11 or newer. Detailed information is available in the official project announcement at https://community.openvpn.net/openvpn/wiki/CVE-2024-5594. Users of Debian distributions should install patches described in the Debian LTS security announcement.

Who is affected

OpenVPN in all versions before 2.6.11

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Openvpn

    APP
    Openvpn
    2.6.0 – 2.6.11 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2025-12106CRITICAL9.1PL ✓same product

OpenVPN: heap buffer over-read przy parsowaniu adresów IP

CVE-2024-27903CRITICAL9.8PL ✓same product

OpenVPN dla Windows — ładowanie wtyczek z dowolnego katalogu

CVE-2023-46850CRITICAL9.8PL ✓same product

Use-after-free w OpenVPN 2.6.0–2.6.6 umożliwiający RCE

CVE-2022-0547CRITICAL9.8PL ✓same product

OpenVPN: Authentication Bypass przez wtyczki z odroczoną autoryzacją

CVE-2018-7544CRITICAL9.1PL ✓same product

OpenVPN: cross-protocol scripting przez interfejs zarządzania TCP