CVE-2024-8474

Published Jan 6, 2025

Last updated 2 months ago

Overview

Description
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
Source
security@openvpn.net
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

security@openvpn.net
CWE-212

Social media

Hype score
Not currently trending
  1. ''CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys'' #infosec #pentest #redteam #blueteam https://t.co/xSk32W9NL3

    @CyberWarship

    23 Jan 2025

    2127 Impressions

    12 Retweets

    14 Likes

    3 Bookmarks

    0 Replies

    1 Quote

  2. La mia POV per Openvpn e la sua vulnerabilità CVE-2024-8474. https://t.co/YV7hVgoWAO

    @ricca9380

    9 Jan 2025

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys https://t.co/VtwLB8Im77

    @tmersany

    7 Jan 2025

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys https://t.co/xETRpz1OAT

    @elhackernet

    7 Jan 2025

    6885 Impressions

    53 Retweets

    120 Likes

    31 Bookmarks

    1 Reply

    2 Quotes

  5. 🚨 CVE Alert: OpenVPN Connect Information Disclosure Vulnerability🚨 Vulnerability Details: CVE-2024-8474 (CVSS 7.5/10) OpenVPN Connect Information Disclosure Vulnerability Impact A successful exploit may allow an attacker to access a user's device, extract the private key from

    @CyberxtronTech

    7 Jan 2025

    83 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys https://t.co/XAVnF84GFM

    @Dinosn

    7 Jan 2025

    24720 Impressions

    160 Retweets

    457 Likes

    154 Bookmarks

    2 Replies

    1 Quote

  7. OpenVPN Connect Vulnerability Leaks Private Keys Discover the vulnerability (CVE-2024-8474) that could have exposed your private keys and decrypted your VPN traffic. Stay protected with a secure VPN connection https://t.co/RTkv4Yapt0

    @the_yellow_fall

    7 Jan 2025

    857 Impressions

    8 Retweets

    15 Likes

    5 Bookmarks

    1 Reply

    0 Quotes