PT-2025-21991 · Openvpn · Openvpn 3 Linux

Wolfgang Frisch

·

Published

2025-05-19

·

Updated

2025-06-12

·

CVE-2025-3908

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OpenVPN 3 Linux versions 20 through 24
Description: The configuration initialization tool in OpenVPN 3 Linux allows a local attacker to use symlinks pointing at an arbitrary directory, which will change the ownership and permissions of that destination directory.
Recommendations: For OpenVPN 3 Linux versions 20 through 24, consider restricting the use of the configuration initialization tool until a patch is available to prevent local attackers from exploiting symlinks to alter directory permissions.

Fix

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-09972
CVE-2025-3908

Affected Products

Openvpn 3 Linux