QID 375879
Date Published: 2021-09-23
QID 375879: Open Virtual Private Network (OpenVPN) Access Server Cross-Site Request Forgery (CSRF) Vulnerability
OpenVPN Access Server is a full featured SSL VPN software solution that integrates OpenVPN server capabilities, enterprise management capabilities, simplified OpenVPN Connect UI, and OpenVPN Client software packages that accommodate Windows, MAC, and Linux, mobile OS (Android and iOS) environments.
CVE-2013-2692: OpenVPN Access Server before 1.8.5 is vulnerable with Cross-site request forgery (CSRF) vulnerability in the Admin web interface.
Affected Versions:
OpenVPN-AS Version prior to 1.8.5
QID Detection Logic:(Authenticated)
The QID checks for vulnerable version of OpenVPN Access server by checking its version file on linux systems.
Successful exploitation of this vulnerability may allow remote attackers to hijack the authentication of administrators for requests that create administrative users using CSRF vulnerability.
CVEs related to QID 375879
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenVPN Access Server HomePage |
|