VYPR
Medium severity6.1NVD Advisory· Published Sep 23, 2021· Updated Jun 17, 2026

CVE-2021-3824

CVE-2021-3824

Description

OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.

Affected products

3
  • OpenVPN/Openvpn Access Serverllm-fuzzy3 versions
    2.9.0 - 2.9.4+ 2 more
    • (no CPE)range: 2.9.0 - 2.9.4
    • (no CPE)
    • cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*range: >=2.9.0,<=2.9.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.