Medium severity6.1NVD Advisory· Published Sep 23, 2021· Updated Jun 17, 2026
CVE-2021-3824
CVE-2021-3824
Description
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
Affected products
3cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*range: >=2.9.0,<=2.9.4
- (no CPE)range: 2.9.0 - 2.9.4
- OpenVPN/OpenVPN Access Serverdescription
Patches
Vulnerability mechanics
References
1- openvpn.net/vpn-server-resources/release-notes/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.