OpenVPN Access Server Desktop Client Cross Site Request Forgery Vulnerability
BID:68666
Info
OpenVPN Access Server Desktop Client Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 68666 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9104 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2014 12:00AM |
| Updated: | Dec 03 2014 12:55AM |
| Credit: | Stefan Viehböck from SEC Consult Vulnerability Lab. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenVPN Access Server Desktop Client Cross Site Request Forgery Vulnerability
OpenVPN Access Server Desktop Client is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to execute arbitrary code and perform certain unauthorized actions in the context of the affected application. Other attacks are also possible.
OpenVPN Access Server Desktop Client 1.5.6 is vulnerable; other versions may also be affected.
OpenVPN Access Server Desktop Client is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to execute arbitrary code and perform certain unauthorized actions in the context of the affected application. Other attacks are also possible.
OpenVPN Access Server Desktop Client 1.5.6 is vulnerable; other versions may also be affected.
Exploit / POC
OpenVPN Access Server Desktop Client Cross Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
Solution / Fix
OpenVPN Access Server Desktop Client Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenVPN Access Server Desktop Client Cross Site Request Forgery Vulnerability
References:
References: