CVE-2024-8474 Details
Description
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
A vulnerability exists in OpenVPN Connect for Android, prior to version 3.5.0, where the configuration profile's private key is stored in clear text and logged within the application. This exposed private key can be intercepted by an unauthorized actor and used to decrypt VPN traffic.
Users are advised to update OpenVPN Connect for Android to version 3.5.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://openvpn.net/connect-docs/android-release-notes.html | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openvpn connect | < 3.5.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2025 | Initial Analysis | [email protected] |
| Jan 6, 2025 | CVE Modified | CISA-ADP |
| Jan 6, 2025 | New CVE Received | [email protected] |