OpenVPN Inc.

First CVE: Jul 14, 2020Active for: 6 years
48
CVEs Published
More CVEs Published than 56% of tracked CNAs
6.9
Avg CVEs / Year
More Avg CVEs / Year than 41% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by OpenVPN Inc. as a CNA, 95.8% affect products that OpenVPN Inc. develops as a vendor.

95.8%
Self-reported: 46Third-party: 2

Of all the CVEs published that affect products developed by OpenVPN Inc., 60.5% are self-published by OpenVPN Inc. as a CNA.

60.5%
39.5%
Self-published: 46Published by other CNAs: 30

Trends Over Time

The number and severity of CVEs published by OpenVPN Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2020
6 years ago
Most Recent CVE
Jul 8, 2026
17 days ago

Top CVEs

All CVEs published by OpenVPN Inc. as a CNA, regardless of affected vendor or product.

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting i
Jul 8, 20249.839NONO
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC ch
May 26, 20267.837NONO
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use
Oct 24, 20258.836NONO
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially
Jul 6, 20267.534NONO
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behi
Jul 8, 20267.533NONO
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact w
Jul 8, 20249.833NONO
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
Nov 11, 20239.832NONO
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, w
Mar 18, 20229.832NONO
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fat
Jun 8, 20266.931NONO
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
Dec 1, 20259.131NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA48 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local16 (33.3%)
Network32 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (81.3%)
High9 (18.8%)
Unknown0 (0.0%)
User Interaction
None42 (87.5%)
Unknown0 (0.0%)
Required3 (6.3%)
Privileges Required
Low21 (43.8%)
High0 (0.0%)
None27 (56.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by OpenVPN Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by OpenVPN Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs