OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentials
2023-10-17T13:15:11.573
2024-11-21T07:20:11.653
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openvpn | connect | < 3.4.0.3121 | Yes |
Application | openvpn | connect | < 3.4.0.4506 | Yes |