CVE-2006-2229

UnknownEPSS 1.35%

Last modified

CVE-2006-2229 is a vulnerability of currently unknown severity. OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.. EPSS estimates a 1.35% chance of exploitation in the next 30 days.

Description

OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.

Metrics

EPSS Probability
1.35%

67.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
OpenvpnOpenvpn2.0
OpenvpnOpenvpn2.0.1_rc1
OpenvpnOpenvpn2.0.1_rc2
OpenvpnOpenvpn2.0.1_rc3
OpenvpnOpenvpn2.0.1_rc4
OpenvpnOpenvpn2.0.1_rc5
OpenvpnOpenvpn2.0.1_rc6
OpenvpnOpenvpn2.0.1_rc7
OpenvpnOpenvpn2.0.2_rc1
OpenvpnOpenvpn2.0.3_rc1
OpenvpnOpenvpn2.0.4
OpenvpnOpenvpn2.0.6_rc1
OpenvpnOpenvpn2.0_beta1
OpenvpnOpenvpn2.0_beta2
OpenvpnOpenvpn2.0_beta3
OpenvpnOpenvpn2.0_beta4
OpenvpnOpenvpn2.0_beta5
OpenvpnOpenvpn2.0_beta6
OpenvpnOpenvpn2.0_beta7
OpenvpnOpenvpn2.0_beta8
OpenvpnOpenvpn2.0_beta9
OpenvpnOpenvpn2.0_beta10
OpenvpnOpenvpn2.0_beta11
OpenvpnOpenvpn2.0_beta12
OpenvpnOpenvpn2.0_beta13
OpenvpnOpenvpn2.0_beta15
OpenvpnOpenvpn2.0_beta16
OpenvpnOpenvpn2.0_beta17
OpenvpnOpenvpn2.0_beta18
OpenvpnOpenvpn2.0_beta19
OpenvpnOpenvpn2.0_beta20
OpenvpnOpenvpn2.0_beta28
OpenvpnOpenvpn2.0_rc1
OpenvpnOpenvpn2.0_rc2
OpenvpnOpenvpn2.0_rc3
OpenvpnOpenvpn2.0_rc4
OpenvpnOpenvpn2.0_rc5
OpenvpnOpenvpn2.0_rc6
OpenvpnOpenvpn2.0_rc7
OpenvpnOpenvpn2.0_rc8
OpenvpnOpenvpn2.0_rc9
OpenvpnOpenvpn2.0_rc10
OpenvpnOpenvpn2.0_rc11
OpenvpnOpenvpn2.0_rc12
OpenvpnOpenvpn2.0_rc13
OpenvpnOpenvpn2.0_rc14
OpenvpnOpenvpn2.0_rc15
OpenvpnOpenvpn2.0_rc16
OpenvpnOpenvpn2.0_rc17
OpenvpnOpenvpn2.0_rc18

Showing 50 of 85 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-2229?
OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.
How severe is CVE-2006-2229?
Severity scoring for CVE-2006-2229 is pending analysis. The EPSS model estimates a 1.35% probability of exploitation in the next 30 days.
How do I fix CVE-2006-2229?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-2229?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST