logo

All Roads Lead to OpenVPN: Pwning Industrial Remote Access Clients

ID: db53d4fc-8e9f-59a9-b60d-1f0308e3393c

STIX ID: report--db53d4fc-8e9f-59a9-b60d-1f0308e3393c

Feed Name: Claroty Team82

Threat Score
85/100

Date Published: 2023-10-16

Date Updated: 2026-04-17

Author: Sharon Brizinov

...
...

Claroty Team82 analyzed VPN client products that embed OpenVPN and uncovered a class of vulnerabilities where an unauthenticated local management interface combined with browser-origin blind SSRF allows an attacker to force the client to load attacker-hosted OpenVPN configuration files (including SMB/UNC paths) that use OpenVPN script directives (e.g., "up") to execute arbitrary commands as SYSTEM; the report provides PoC details, affected vendors and CVEs, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.