Improper access control in OpenVPN for Windows - CVE-2024-24974

 

Improper access control in OpenVPN for Windows - CVE-2024-24974

Published: March 20, 2024 / Updated: March 25, 2024


Vulnerability identifier: #VU87676
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-24974
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions to the interactive service pipe. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.

The vulnerability affects Windows installations only.


Affected software

OpenVPN for Windows
SINEMA Remote Connect Client

How to mitigate CVE-2024-24974

Install updates from vendor's website.

OpenVPN for Windows - addressed in versions 2.5.10, 2.6.10
SINEMA Remote Connect Client - update to 3.2 SP3

External References

Related Security Bulletins