Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-25166
HistoryApr 14, 2022 - 4:15 p.m.

Design/Logic Flaw

2022-04-1416:15:00
PRIOn knowledge base
www.prio-n.com
3

5 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.9%

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user’s Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

CPENameOperatorVersion
aws_client_vpneq2.0.0

5 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.9%

Related for PRION:CVE-2022-25166