PT-2025-21991 · Openvpn · Openvpn 3 Linux
Wolfgang Frisch
·
Published
2025-05-19
·
Updated
2025-06-12
·
CVE-2025-3908
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenVPN 3 Linux versions 20 through 24
Description:
The configuration initialization tool in OpenVPN 3 Linux allows a local attacker to use symlinks pointing at an arbitrary directory, which will change the ownership and permissions of that destination directory.
Recommendations:
For OpenVPN 3 Linux versions 20 through 24, consider restricting the use of the configuration initialization tool until a patch is available to prevent local attackers from exploiting symlinks to alter directory permissions.
Fix
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openvpn 3 Linux