OpenVPN Connect Clear-Text Private Key Logging Vulnerability on Android

Vulnerability

A vulnerability exists in OpenVPN Connect for Android, prior to version 3.5.0, where the configuration profile's private key is stored in clear text and logged within the application. This exposed private key can be intercepted by an unauthorized actor and used to decrypt VPN traffic.

Impact

Exploitation of this vulnerability allows for the decryption of VPN traffic, potentially exposing sensitive data transmitted over the VPN connection.

Remediation

Users are advised to update OpenVPN Connect for Android to version 3.5.0 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.