PT-2024-3588 · Openvpn · Openvpn Connect
Mykola Grymalyuk
·
Published
2024-01-18
·
Updated
2025-04-02
·
CVE-2023-7245
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenVPN Connect versions 3.0 through 3.4.3 (Windows)
OpenVPN Connect versions 3.0 through 3.4.7 (macOS)
Description
The issue is related to the nodejs framework in OpenVPN Connect, which was not properly configured. This configuration issue allows a local user to execute arbitrary code within the nodejs process context via the
ELECTRON RUN AS NODE environment variable. The vulnerability is also described as being related to the failure to neutralize instructions in dynamically executed code, which can allow an attacker to execute arbitrary code.Recommendations
For OpenVPN Connect versions 3.0 through 3.4.3 (Windows), update to a version later than 3.4.3.
For OpenVPN Connect versions 3.0 through 3.4.7 (macOS), update to a version later than 3.4.7.
As a temporary workaround, consider restricting access to the
ELECTRON RUN AS NODE environment variable to minimize the risk of exploitation.Fix
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openvpn Connect