CVE-2017-5868
Last modified
CVE-2017-5868 is a vulnerability of currently unknown severity. CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters in the PATH_INFO to __session_start__/.. EPSS estimates a 4.62% chance of exploitation in the next 30 days.
Description
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters in the PATH_INFO to __session_start__/.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openvpn | Openvpn Access Server | 2.1.4 |
References
- http://www.openwall.com/lists/oss-security/2017/05/23/13Exploit, Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1038547Third Party Advisory, VDB Entry
- https://sysdream.com/news/lab/2017-05-05-cve-2017-5868-openvpn-access-server-crlf-injection-with-session-fixation/Exploit, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/05/23/13Exploit, Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1038547Third Party Advisory, VDB Entry
- https://sysdream.com/news/lab/2017-05-05-cve-2017-5868-openvpn-access-server-crlf-injection-with-session-fixation/Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5868?
How severe is CVE-2017-5868?
How do I fix CVE-2017-5868?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5861Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-5863Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected…
- CVE-2017-5864Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected…
- CVE-2017-5865The password reset functionality in ownCloud Server before 8…
- CVE-2017-5866The autocomplete feature in the E-Mail share dialog in ownCl…
- CVE-2017-5867ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x bef…
- CVE-2017-5869Directory traversal vulnerability in the file import feature…
- CVE-2017-5870Multiple cross-site scripting (XSS) vulnerabilities in ViMbA…
- CVE-2017-5871Odoo Version <= 8.0-20160726 and Version 9 is affected by: C…
- CVE-2017-5872The TCP/IP networking module in Unisys ClearPath MCP systems…
- CVE-2017-5873Unquoted Windows search path vulnerability in the guest serv…
- CVE-2017-5874CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05E…
Are you affected by CVE-2017-5868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
