VYPR

OpenVPN

by Aviatrix

CVEs (2)

  • CVE-2020-7224CriApr 16, 2020
    risk 0.64cvss 9.8epss 0.02

    The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

  • CVE-2020-27569HigApr 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.