Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API...
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting established VPN sessions, (2) connect to arbitrary VPN servers, or (3) create VPN profiles and execute arbitrary commands via crafted API requests.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9104
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/532795/100/0/threaded
- http://seclists.org/fulldisclosure/2014/Jul/76
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140716-1_OpenVPN_Access_Server_Desktop_Client_Remote_Code_Execution_via_CSRF_v10.txt
- http://openvpn.net/index.php/access-server/security-advisories.html
- https://www.youtube.com/watch?v=qhgysgfvQh8
More from openvpn
View All →Affected Vendor
openvpn
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.