Lucene search

K
cvelistMitreCVELIST:CVE-2017-5868
HistoryMay 25, 2017 - 7:00 p.m.

CVE-2017-5868

2017-05-2519:00:00
mitre
www.cve.org
2

AI Score

6.4

Confidence

High

EPSS

0.003

Percentile

70.7%

CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via “%0A” characters in the PATH_INFO to session_start/.

AI Score

6.4

Confidence

High

EPSS

0.003

Percentile

70.7%

Related for CVELIST:CVE-2017-5868