CVE detail
CVE-2021-27406 — CVE-2021-27406
Published 2022-10-14 · Modified 2026-06-17 · Vendor perfact · Product openvpn-client · Source nvd
HIGH
severity
CVSS-derived band
0.0096
EPSS probability
exploitation probability, 30d
58.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This could result in the attacker achieving execution with privileges of a SYSTEM user.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References