Security Advisory

CVE-2024-8474

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-01-06 14:33:26
Last updated 2025-01-06 16:54:38
Assigner OpenVPN
State PUBLISHED

Description

OpenVPN Connect before version 3.5.0 can contain the configuration profiles clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic