Cross-Site Request Forgery Vulnerabilities in OpenVPN Access Server Desktop Client
CVE-2014-9104

Currently unrated

Key Information:

Vendor

Openvpn

Vendor
CVE Published:
26 November 2014

What is CVE-2014-9104?

OpenVPN Access Server's Desktop Client has multiple vulnerabilities that allow remote attackers to exploit the XML-RPC API. These vulnerabilities can lead to unauthorized actions such as disconnecting active VPN sessions, connecting to unauthorized VPN servers, or creating new VPN profiles. Attackers may execute arbitrary commands through specially crafted API requests, compromising the integrity and confidentiality of the VPN service.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2014-9104 : Cross-Site Request Forgery Vulnerabilities in OpenVPN Access Server Desktop Client