Lucene search

K
cvelistOpenVPNCVELIST:CVE-2023-7245
HistoryFeb 20, 2024 - 11:08 a.m.

CVE-2023-7245

2024-02-2011:08:29
CWE-95
OpenVPN
www.cve.org
openvpn
connect
framework
misconfiguration
vulnerability
nodejs
process
electron_run_as_node
environment variable

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable

CNA Affected

[
  {
    "vendor": "OpenVPN",
    "product": "OpenVPN Connect",
    "platforms": [
      "Windows",
      "MacOS"
    ],
    "versions": [
      {
        "status": "affected",
        "version": "3.0 (Windows)",
        "lessThanOrEqual": "3.4.3",
        "versionType": "minor releases"
      },
      {
        "status": "affected",
        "version": "3.0 (macOS) ",
        "lessThanOrEqual": "3.4.7",
        "versionType": "minor releases"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for CVELIST:CVE-2023-7245