Back to search
CVE-2024-5594
Published: Jan 6, 2025
Modified: Nov 3, 2025
PUBLISHED
Description
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
| Vendor | Product | Versions |
|---|---|---|
OpenVPN | OpenVPN | affected 0 - < 2.6.11 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now