PT-2021-3953 · Openvpn · Openvpn Connect
Xavier Danest
·
Published
2021-06-23
·
Updated
2021-07-09
·
CVE-2021-3613
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenVPN Connect versions 3.2.0 through 3.3.0
Description
The issue is related to the mechanism of system library calls in OpenVPN Connect, allowing local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present. This enables the user to run arbitrary code with the same privilege level as the main OpenVPN process.
Recommendations
For versions 3.2.0 through 3.3.0, consider restricting access to the OpenSSL configuration file to prevent loading of arbitrary libraries until a patch is available. As a temporary workaround, disabling the use of dynamic loadable libraries may help minimize the risk of exploitation.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openvpn Connect