Description
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
Published: 2024-07-08
Score: 7.5 High
EPSS: 11.1% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.09711}

epss

{'score': 0.09949}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2024-08-10T03:55:21.896Z

Reserved: 2024-03-12T18:26:01.713Z

Link: CVE-2024-24974

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.292Z

cve-icon NVD

Status : Modified

Published: 2024-07-08T11:15:10.103

Modified: 2024-11-21T09:00:04.127

Link: CVE-2024-24974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses