OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://openvpn.net/man.html - | |
References | () http://www.osvdb.org/25660 - | |
References | () http://www.securityfocus.com/archive/1/432863/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/432867/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/433000/100/0/threaded - |
Information
Published : 2006-05-05 19:02
Updated : 2024-11-21 00:10
NVD link : CVE-2006-2229
Mitre link : CVE-2006-2229
CVE.ORG link : CVE-2006-2229
JSON object : View
Products Affected
openvpn
- openvpn
- openvpn_access_server
CWE