Database/Control plane, storage & DevOps
OpenVPN: The interactive service pipe is reachable remotely
CVSS 7.5CVE-2024-24974Control plane, storage & DevOpscurated
Impact
The interactive service pipe is reachable remotely -> interact with the privileged OpenVPN service
Who can reach it
Network (remote)
What to do
Control-plane: patch; restrict the service named pipe
References
Related entries
- OpenVPN: Corrupting and replaying early-handshake packets against a tls-crypt-v2 serverCVE-2025-2704 · OpenVPNHigh
- OpenVPN: Stack overflow in the interactive serviceCVE-2024-27459 · OpenVPNHigh
- Intel Neural Compressor: Unauthenticated input-validation failure leading to escalation of privilege in NeuralCVE-2024-28028 · Intel Neural CompressorHigh
- Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0a: Three defects that together mean every SANnav OVACVE-2024-29966 · Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0aHigh
- AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014): The BadRAM SPD-aliasing technique aimed atCVE-2024-36354 · AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014)High
- Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an emptyCVE-2024-47866 · Ceph RADOS Gateway (RGW)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.