Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mr. Ka Lok Wu

Pesquisador deThe Chinese University of Hong Kong
#44341de 53,639
5.9CVSS total
Vulnerabilidades · 1
PT-2023-6378
5.9
2023-10-17
Openvpn · Openvpn Connect · CVE-2022-3761
**Name of the Vulnerable Software and Affected Versions** OpenVPN Connect versions before 3.4.0.4506 (macOS) OpenVPN Connect versions before 3.4.0.3100 (Windows) **Description** The issue is related to errors in the certificate authentication procedure, allowing a remote attacker to perform a man-in-the-middle attack. This can lead to the interception of configuration profile download requests, which may contain user credentials. **Recommendations** For OpenVPN Connect versions before 3.4.0.4506 (macOS), update to version 3.4.0.4506 or later. For OpenVPN Connect versions before 3.4.0.3100 (Windows), update to version 3.4.0.3100 or later. As a temporary workaround, consider restricting access to sensitive configuration profiles until a patch is applied.