PT-2023-6378 · Openvpn · Openvpn Connect
Mr. Ka Lok Wu
·
Published
2023-10-17
·
Updated
2023-10-24
·
CVE-2022-3761
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenVPN Connect versions before 3.4.0.4506 (macOS)
OpenVPN Connect versions before 3.4.0.3100 (Windows)
Description
The issue is related to errors in the certificate authentication procedure, allowing a remote attacker to perform a man-in-the-middle attack. This can lead to the interception of configuration profile download requests, which may contain user credentials.
Recommendations
For OpenVPN Connect versions before 3.4.0.4506 (macOS), update to version 3.4.0.4506 or later.
For OpenVPN Connect versions before 3.4.0.3100 (Windows), update to version 3.4.0.3100 or later.
As a temporary workaround, consider restricting access to sensitive configuration profiles until a patch is applied.
Fix
Improper Authentication
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openvpn Connect