PT-2021-3953 · Openvpn · Openvpn Connect

Xavier Danest

·

Published

2021-06-23

·

Updated

2021-07-09

·

CVE-2021-3613

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN Connect versions 3.2.0 through 3.3.0
Description The issue is related to the mechanism of system library calls in OpenVPN Connect, allowing local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present. This enables the user to run arbitrary code with the same privilege level as the main OpenVPN process.
Recommendations For versions 3.2.0 through 3.3.0, consider restricting access to the OpenSSL configuration file to prevent loading of arbitrary libraries until a patch is available. As a temporary workaround, disabling the use of dynamic loadable libraries may help minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04471
CVE-2021-3613

Affected Products

Openvpn Connect