CVE-2024-28882
OpenVPN vulnerability analysis and mitigation

Overview

OpenVPN versions from 2.6.0 through 2.6.10, when operating in a server role, contain a vulnerability where the server accepts multiple exit notifications from authenticated clients, which can extend the validity of a closing session. This vulnerability was assigned CVE-2024-28882 and was publicly disclosed on July 8, 2024 (NVD).

Technical details

The vulnerability is classified as CWE-772 (Missing Release of Resource after Effective Lifetime). The issue was introduced in version 2.6.0 beta1 through commit d468dff7bdfd79059818c190ddf41b125bb658de and has been assigned a CVSS 3.1 base score of 4.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L (Debian Tracker, NVD).

Impact

The vulnerability affects resource management in OpenVPN servers, potentially leading to extended session validity beyond intended timeframes. This could impact server resource availability and session management capabilities (NVD).

Mitigation and workarounds

The vulnerability has been fixed in OpenVPN version 2.6.11 through commit 65fb67cd6c320a426567b2922c4282fb8738ba3f. Users are advised to upgrade to this version or later. Several distributions have also released fixed packages, including Ubuntu 24.04 LTS (2.6.9-1ubuntu4.1) and Ubuntu 23.10 (2.6.5-0ubuntu1.2) (Ubuntu Security, Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related OpenVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12106CRITICAL9.1
  • OpenVPNOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoNoDec 01, 2025
CVE-2025-10680HIGH8.8
  • OpenVPNOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoNoOct 24, 2025
CVE-2024-4877HIGH8.8
  • OpenVPNOpenVPN
  • openvpn
NoYesApr 03, 2025
CVE-2025-13086MEDIUM4.6
  • OpenVPNOpenVPN
  • openvpn
NoYesDec 03, 2025
CVE-2025-13751LOW1.3
  • OpenVPNOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoNoDec 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management