Lucene search

K
cvelistMitreCVELIST:CVE-2022-25166
HistoryApr 14, 2022 - 3:18 p.m.

CVE-2022-25166

2022-04-1415:18:53
mitre
www.cve.org
1

5.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.9%

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user’s Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

5.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.9%

Related for CVELIST:CVE-2022-25166