CVE-2006-2229
OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause…
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:N/A:P
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- openvpn/openvpn · openvpn/openvpn access server
- Source
- cve@mitre.org
References
- http://openvpn.net/man.html
- http://www.osvdb.org/25660
- http://www.securityfocus.com/archive/1/432863/100/0/threaded
- http://www.securityfocus.com/archive/1/432867/100/0/threaded
- http://www.securityfocus.com/archive/1/433000/100/0/threaded
- http://openvpn.net/man.html
- http://www.osvdb.org/25660
- http://www.securityfocus.com/archive/1/432863/100/0/threaded
- http://www.securityfocus.com/archive/1/432867/100/0/threaded
- http://www.securityfocus.com/archive/1/433000/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.