WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Vulnerability in Multiple VPN Applications
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Vulnerability in Multiple VPN Applications

Author: Charles Egli

Created: Tuesday, April 16, 2019 - 15:00

Categories: Cybersecurity

The National Cybersecurity and Communications Integration Center (NCCIC) has issued an advisory regarding the recent release of information on a vulnerability affecting multiple Virtual Private Network (VPN) applications, which are used to create secure connections with another network over the Internet. The CERT Coordination Center at Carnegie Mellon University was the first to publish an advisory on the vulnerability, which identifies the root of the problem as the applications storing authentication and/or cookies insecurely in memory and/or file logs. According to the CERT Coordination Center, if attackers have persistent access to a VPN user’s endpoint or exfiltrates the cookie using other methods, they can replay the session and bypass other authentication methods. Attackers would then have access to the same applications that the user does through their VPN session. The advisory identifies the VPN applications affected by the vulnerability and the status of product updates. Read the advisory at the CERT Coordination Center.

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar