Vulnerability Description
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openvpn | Openvpn Gui | < 2.6.9 |
Related Weaknesses (CWE)
References
- https://community.openvpn.net/openvpn/wiki/CVE-2023-7235Permissions Required
- https://community.openvpn.net/openvpn/wiki/CVE-2023-7235Permissions Required
FAQ
What is CVE-2023-7235?
CVE-2023-7235 is a vulnerability with a CVSS score of 8.4 (HIGH). The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which a...
How severe is CVE-2023-7235?
CVE-2023-7235 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-7235?
Check the references section above for vendor advisories and patch information. Affected products include: Openvpn Openvpn Gui.