{"api_version":"1","generated_at":"2026-07-23T11:02:37+00:00","cve":"CVE-2013-2692","urls":{"html":"https://cve.report/CVE-2013-2692","api":"https://cve.report/api/cve/CVE-2013-2692.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-2692","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-2692"},"summary":{"title":"CVE-2013-2692","description":"Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users.","state":"PUBLISHED","assigner":"flexera","published_at":"2014-05-13 14:55:09","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html","name":"http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Release Notes 1.8.5","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/52802","name":"http://secunia.com/advisories/52802","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA52802 - OpenVPN Access Server Cross-Site Request Forgery Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/93111","name":"http://osvdb.org/93111","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-2692","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2692","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"2692","vulnerable":"1","versionEndIncluding":"1.8.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openvpn","cpe5":"openvpn_access_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2013-2692","qid":"375879","title":"Open Virtual Private Network (OpenVPN) Access Server Cross-Site Request Forgery (CSRF) Vulnerability"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T15:44:33.137Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"52802","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/52802"},{"name":"93111","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/93111"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-05-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-05-13T13:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"52802","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/52802"},{"name":"93111","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/93111"},{"tags":["x_refsource_CONFIRM"],"url":"http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2013-2692","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"52802","refsource":"SECUNIA","url":"http://secunia.com/advisories/52802"},{"name":"93111","refsource":"OSVDB","url":"http://osvdb.org/93111"},{"name":"http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html","refsource":"CONFIRM","url":"http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2013-2692","datePublished":"2014-05-13T14:00:00.000Z","dateReserved":"2013-03-26T00:00:00.000Z","dateUpdated":"2024-08-06T15:44:33.137Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-05-13 14:55:09","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*","versionEndIncluding":"1.8.4","matchCriteriaId":"A5DDB0E3-20AF-45B1-A91E-14CD795F4D11"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"2692","Ordinal":"1","Title":"CVE-2013-2692","CVE":"CVE-2013-2692","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"2692","Ordinal":"1","NoteData":"Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users.","Type":"Description","Title":"CVE-2013-2692"},{"CveYear":"2013","CveId":"2692","Ordinal":"2","NoteData":"2014-05-13","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"2692","Ordinal":"3","NoteData":"2014-05-13","Type":"Other","Title":"Modified"}]}}}