CVE-2023-7235

The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openvpn:openvpn_gui:*:*:*:*:*:*:*:*

History

06 May 2025, 18:02

Type Values Removed Values Added
CPE cpe:2.3:a:openvpn:openvpn_gui:*:*:*:*:*:*:*:*
References () https://community.openvpn.net/openvpn/wiki/CVE-2023-7235 - () https://community.openvpn.net/openvpn/wiki/CVE-2023-7235 - Permissions Required
First Time Openvpn openvpn Gui
Openvpn

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://community.openvpn.net/openvpn/wiki/CVE-2023-7235 - () https://community.openvpn.net/openvpn/wiki/CVE-2023-7235 -

26 Aug 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4

22 Feb 2024, 19:07

Type Values Removed Values Added
Summary
  • (es) El instalador de la GUI de OpenVPN anterior a la versión 2.6.9 no establecía las restricciones de control de acceso adecuadas al directorio de instalación de los archivos binarios de OpenVPN cuando usaba una ruta de instalación no estándar, lo que permite a un atacante reemplazar archivos binarios para ejecutar ejecutables arbitrarios.

21 Feb 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 11:15

Updated : 2025-05-06 18:02


NVD link : CVE-2023-7235

Mitre link : CVE-2023-7235

CVE.ORG link : CVE-2023-7235


JSON object : View

Products Affected

openvpn

  • openvpn_gui
CWE
CWE-276

Incorrect Default Permissions