OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.
2006-05-05T19:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:N/A:P
4.9
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openvpn | openvpn | 2.0 | Yes |
| Application | openvpn | openvpn | 2.0.1_rc1 | Yes |
| Application | openvpn | openvpn | 2.0.1_rc2 | Yes |
| Application | openvpn | openvpn | 2.0.1_rc3 | Yes |
| Application | openvpn | openvpn | 2.0.1_rc4 | Yes |
| Application | openvpn | openvpn | 2.0.1_rc5 | Yes |
| Application | openvpn | openvpn | 2.0.1_rc6 | Yes |
| Application | openvpn | openvpn | 2.0.1_rc7 | Yes |
| Application | openvpn | openvpn | 2.0.2_rc1 | Yes |
| Application | openvpn | openvpn | 2.0.3_rc1 | Yes |
| Application | openvpn | openvpn | 2.0.4 | Yes |
| Application | openvpn | openvpn | 2.0.6_rc1 | Yes |
| Application | openvpn | openvpn | 2.0_beta1 | Yes |
| Application | openvpn | openvpn | 2.0_beta2 | Yes |
| Application | openvpn | openvpn | 2.0_beta3 | Yes |
| Application | openvpn | openvpn | 2.0_beta4 | Yes |
| Application | openvpn | openvpn | 2.0_beta5 | Yes |
| Application | openvpn | openvpn | 2.0_beta6 | Yes |
| Application | openvpn | openvpn | 2.0_beta7 | Yes |
| Application | openvpn | openvpn | 2.0_beta8 | Yes |
| Application | openvpn | openvpn | 2.0_beta9 | Yes |
| Application | openvpn | openvpn | 2.0_beta10 | Yes |
| Application | openvpn | openvpn | 2.0_beta11 | Yes |
| Application | openvpn | openvpn | 2.0_beta12 | Yes |
| Application | openvpn | openvpn | 2.0_beta13 | Yes |
| Application | openvpn | openvpn | 2.0_beta15 | Yes |
| Application | openvpn | openvpn | 2.0_beta16 | Yes |
| Application | openvpn | openvpn | 2.0_beta17 | Yes |
| Application | openvpn | openvpn | 2.0_beta18 | Yes |
| Application | openvpn | openvpn | 2.0_beta19 | Yes |
| Application | openvpn | openvpn | 2.0_beta20 | Yes |
| Application | openvpn | openvpn | 2.0_beta28 | Yes |
| Application | openvpn | openvpn | 2.0_rc1 | Yes |
| Application | openvpn | openvpn | 2.0_rc2 | Yes |
| Application | openvpn | openvpn | 2.0_rc3 | Yes |
| Application | openvpn | openvpn | 2.0_rc4 | Yes |
| Application | openvpn | openvpn | 2.0_rc5 | Yes |
| Application | openvpn | openvpn | 2.0_rc6 | Yes |
| Application | openvpn | openvpn | 2.0_rc7 | Yes |
| Application | openvpn | openvpn | 2.0_rc8 | Yes |
| Application | openvpn | openvpn | 2.0_rc9 | Yes |
| Application | openvpn | openvpn | 2.0_rc10 | Yes |
| Application | openvpn | openvpn | 2.0_rc11 | Yes |
| Application | openvpn | openvpn | 2.0_rc12 | Yes |
| Application | openvpn | openvpn | 2.0_rc13 | Yes |
| Application | openvpn | openvpn | 2.0_rc14 | Yes |
| Application | openvpn | openvpn | 2.0_rc15 | Yes |
| Application | openvpn | openvpn | 2.0_rc16 | Yes |
| Application | openvpn | openvpn | 2.0_rc17 | Yes |
| Application | openvpn | openvpn | 2.0_rc18 | Yes |
| Application | openvpn | openvpn | 2.0_rc19 | Yes |
| Application | openvpn | openvpn | 2.0_rc20 | Yes |
| Application | openvpn | openvpn | 2.0_rc21 | Yes |
| Application | openvpn | openvpn | 2.0_test1 | Yes |
| Application | openvpn | openvpn | 2.0_test2 | Yes |
| Application | openvpn | openvpn | 2.0_test3 | Yes |
| Application | openvpn | openvpn | 2.0_test4 | Yes |
| Application | openvpn | openvpn | 2.0_test5 | Yes |
| Application | openvpn | openvpn | 2.0_test6 | Yes |
| Application | openvpn | openvpn | 2.0_test7 | Yes |
| Application | openvpn | openvpn | 2.0_test8 | Yes |
| Application | openvpn | openvpn | 2.0_test9 | Yes |
| Application | openvpn | openvpn | 2.0_test10 | Yes |
| Application | openvpn | openvpn | 2.0_test11 | Yes |
| Application | openvpn | openvpn | 2.0_test12 | Yes |
| Application | openvpn | openvpn | 2.0_test14 | Yes |
| Application | openvpn | openvpn | 2.0_test15 | Yes |
| Application | openvpn | openvpn | 2.0_test16 | Yes |
| Application | openvpn | openvpn | 2.0_test17 | Yes |
| Application | openvpn | openvpn | 2.0_test18 | Yes |
| Application | openvpn | openvpn | 2.0_test19 | Yes |
| Application | openvpn | openvpn | 2.0_test20 | Yes |
| Application | openvpn | openvpn | 2.0_test21 | Yes |
| Application | openvpn | openvpn | 2.0_test22 | Yes |
| Application | openvpn | openvpn | 2.0_test23 | Yes |
| Application | openvpn | openvpn | 2.0_test24 | Yes |
| Application | openvpn | openvpn | 2.0_test25 | Yes |
| Application | openvpn | openvpn | 2.0_test26 | Yes |
| Application | openvpn | openvpn | 2.0_test27 | Yes |
| Application | openvpn | openvpn | 2.0_test29 | Yes |
| Application | openvpn | openvpn_access_server | 2.0.1 | Yes |
| Application | openvpn | openvpn_access_server | 2.0.2 | Yes |
| Application | openvpn | openvpn_access_server | 2.0.5 | Yes |
| Application | openvpn | openvpn_access_server | 2.0.6 | Yes |
| Application | openvpn | openvpn_access_server | 2.0.7 | Yes |