Safervpn offers a VPN client product with a niche vulnerability footprint centered on file-system and permission-management weaknesses, including improper link resolution before file access, incorrect permission assignment for critical resources, and uncontrolled search path elements. These recur across the vendor's core offering and are characteristic of local-privilege and file-handling risks in endpoint security software; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Safervpn over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25744HIGH SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink | Sep 18, 2020 | 8.1 | 25 | NO | NO |
CVE-2020-26050HIGH SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is | Jan 12, 2021 | 7.8 | 24 | NO | NO |
CVE-2018-10647HIGH SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service executes "openvpn.exe" using O | May 2, 2018 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Safervpn.
Media articles that mention a CVE ID that affects a product developed by Safervpn — matched by CVE ID, not by vendor name.