Our takeCCCS warns that OpenVPN versions 2.6.22 and earlier, and 2.7.6 and earlier, contain vulnerabilities. Update to a fixed release if you run it yourself.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Review and apply the OpenVPN advisory (AV26-889). Update any instances running 2.6.22 or earlier to a fixed build, and any running 2.7.6 or earlier to a fixed build.
What this means for you — Lean IT orgs:If you run your own OpenVPN server or client, check the version. Update past 2.6.22 (for the 2.6 series) or past 2.7.6 (for the 2.7 series) as soon as the fixes are available.
What this means for you — MSP:Audit client environments for OpenVPN versions ≤2.6.22 or ≤2.7.6 and schedule updates once the patches are released. Prioritize any internet-facing VPN concentrators.
What this means for you — Researcher:Canadian Cyber Centre advisory AV26-889 flags vulnerabilities in OpenVPN ≤2.6.22 and ≤2.7.6. Review the linked details and test updated builds when available.