The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.
History

Tue, 06 May 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn Gui
CPEs cpe:2.3:a:openvpn:openvpn_gui:*:*:*:*:*:*:*:*
Vendors & Products Openvpn
Openvpn openvpn Gui

Mon, 26 Aug 2024 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published: 2024-02-21T10:55:15.487Z

Updated: 2024-08-26T16:13:36.611Z

Reserved: 2024-01-16T15:21:16.217Z

Link: CVE-2023-7235

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.194Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-21T11:15:07.673

Modified: 2025-05-06T18:02:59.910

Link: CVE-2023-7235

cve-icon Redhat

No data.