Vulnerability Details CVE-2024-8474
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 74.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-8474
-
cpe:2.3:a:openvpn:connect:1.1.17
-
cpe:2.3:a:openvpn:connect:1.1.21
-
cpe:2.3:a:openvpn:connect:1.1.22
-
cpe:2.3:a:openvpn:connect:1.1.23
-
cpe:2.3:a:openvpn:connect:1.1.24
-
cpe:2.3:a:openvpn:connect:1.1.25
-
cpe:2.3:a:openvpn:connect:1.1.26
-
cpe:2.3:a:openvpn:connect:1.1.27
-
cpe:2.3:a:openvpn:connect:3.0.0
-
cpe:2.3:a:openvpn:connect:3.0.0_(820)
-
cpe:2.3:a:openvpn:connect:3.0.0_(870)
-
cpe:2.3:a:openvpn:connect:3.0.1_(884)
-
cpe:2.3:a:openvpn:connect:3.0.1_(885)
-
cpe:2.3:a:openvpn:connect:3.0.1_(895)
-
cpe:2.3:a:openvpn:connect:3.0.1_(918)
-
cpe:2.3:a:openvpn:connect:3.0.2
-
cpe:2.3:a:openvpn:connect:3.0.3
-
cpe:2.3:a:openvpn:connect:3.0.4
-
cpe:2.3:a:openvpn:connect:3.0.5
-
cpe:2.3:a:openvpn:connect:3.0.6
-
cpe:2.3:a:openvpn:connect:3.0.7
-
cpe:2.3:a:openvpn:connect:3.1.0
-
cpe:2.3:a:openvpn:connect:3.1.1
-
cpe:2.3:a:openvpn:connect:3.2.0
-
cpe:2.3:a:openvpn:connect:3.2.1
-
cpe:2.3:a:openvpn:connect:3.2.2
-
cpe:2.3:a:openvpn:connect:3.2.3
-
cpe:2.3:a:openvpn:connect:3.2.4
-
cpe:2.3:a:openvpn:connect:3.2.5
-
cpe:2.3:a:openvpn:connect:3.2.6
-
cpe:2.3:a:openvpn:connect:3.2.7
-
cpe:2.3:a:openvpn:connect:3.3.0
-
cpe:2.3:a:openvpn:connect:3.3.1
-
cpe:2.3:a:openvpn:connect:3.3.2
-
cpe:2.3:a:openvpn:connect:3.3.3
-
cpe:2.3:a:openvpn:connect:3.4.0
-
cpe:2.3:a:openvpn:connect:3.4.2