PT-2023-6378 · Openvpn · Openvpn Connect

Mr. Ka Lok Wu

·

Published

2023-10-17

·

Updated

2023-10-24

·

CVE-2022-3761

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenVPN Connect versions before 3.4.0.4506 (macOS) OpenVPN Connect versions before 3.4.0.3100 (Windows)
Description The issue is related to errors in the certificate authentication procedure, allowing a remote attacker to perform a man-in-the-middle attack. This can lead to the interception of configuration profile download requests, which may contain user credentials.
Recommendations For OpenVPN Connect versions before 3.4.0.4506 (macOS), update to version 3.4.0.4506 or later. For OpenVPN Connect versions before 3.4.0.3100 (Windows), update to version 3.4.0.3100 or later. As a temporary workaround, consider restricting access to sensitive configuration profiles until a patch is applied.

Fix

Improper Authentication

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2023-07090
CVE-2022-3761

Affected Products

Openvpn Connect