• CVE-2023-7235

发布时间: 2024年5月27日

修改时间: 2024年5月27日

概要

The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.

CVSS v3 指标

NVD openEuler
CVSS评分 9.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-2214 The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables. 2024年5月27日

影响产品

产品 状态
KY3.4-4A openvpn Unaffected
KY3.4-5 openvpn Unaffected
KY3.5.1 openvpn Unaffected
KY3.5.2 openvpn Unaffected