PT-2018-18148 · Openvpn+3 · Openvpn+3

Jose Antonio Pérez Piedra

·

Published

2018-03-16

·

Updated

2024-08-05

·

CVE-2018-7544

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN versions through 2.4.5
Description A cross-protocol scripting issue was discovered in the management interface of OpenVPN. When this interface is enabled over TCP without a password and no other clients are connected, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This can be demonstrated by a multipart/form-data POST to "http://localhost:23000" with a "signal SIGTERM" command in a TEXTAREA element. The vendor disputes this as a vulnerability, stating it is the result of improper configuration rather than an intrinsic vulnerability.
Recommendations For OpenVPN versions through 2.4.5, consider disabling the management interface over TCP without a password as a temporary workaround until a more secure configuration can be implemented. Restrict access to the management interface to minimize the risk of exploitation. Avoid using the management interface without proper authentication and authorization mechanisms in place. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1644
CVE-2018-7544
OPENSUSE-SU-2021:0734-1
OPENSUSE-SU-2021_0734-1
OPENSUSE-SU-2024:11692-1
SUSE-SU-2021:14723-1
SUSE-SU-2021:1576-1
SUSE-SU-2021:1577-1
SUSE-SU-2021_14723-1
SUSE-SU-2021_1576-1
SUSE-SU-2021_1577-1

Affected Products

Alt Linux
Debian
Openvpn
Suse