SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-9104

Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting…

MEDIUM 6.8EPSS 0.88%

Does this matter?

Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting established VPN sessions, (2) connect to arbitrary VPN servers, or (3) create VPN profiles and execute arbitrary commands via crafted API requests.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
0.88% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
openvpn/openvpn access server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.