PT-2024-3588 · Openvpn · Openvpn Connect

Mykola Grymalyuk

·

Published

2024-01-18

·

Updated

2025-04-02

·

CVE-2023-7245

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN Connect versions 3.0 through 3.4.3 (Windows) OpenVPN Connect versions 3.0 through 3.4.7 (macOS)
Description The issue is related to the nodejs framework in OpenVPN Connect, which was not properly configured. This configuration issue allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON RUN AS NODE environment variable. The vulnerability is also described as being related to the failure to neutralize instructions in dynamically executed code, which can allow an attacker to execute arbitrary code.
Recommendations For OpenVPN Connect versions 3.0 through 3.4.3 (Windows), update to a version later than 3.4.3. For OpenVPN Connect versions 3.0 through 3.4.7 (macOS), update to a version later than 3.4.7. As a temporary workaround, consider restricting access to the ELECTRON RUN AS NODE environment variable to minimize the risk of exploitation.

Fix

Eval Injection

Weakness Enumeration

Related Identifiers

BDU:2024-03893
CVE-2023-7245

Affected Products

Openvpn Connect