CVE-2013-2692: Openvpn Access Server

Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users.

Affected products

  • Openvpn Openvpn Access Server: up to and including 1.8.4

Published 2014-05-13. Last modified 2026-06-16.