OpenVPN Connect
cpe:2.3:a:openvpn:connect:*:*:*:*:*:*:*
- < 3.5.0
A vulnerability exists in OpenVPN Connect for Android, prior to version 3.5.0, where the configuration profile's private key is stored in clear text and logged within the application. This exposed private key can be intercepted by an unauthorized actor and used to decrypt VPN traffic.
Exploitation of this vulnerability allows for the decryption of VPN traffic, potentially exposing sensitive data transmitted over the VPN connection.
Users are advised to update OpenVPN Connect for Android to version 3.5.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.