CVE-2024-13454: Openvpn Easy-Rsa

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL 3

Affected products

  • Openvpn Easy-Rsa: from 3.0.5, up to and including 3.1.7

Published 2025-01-20. Last modified 2026-06-17.