CVE-2017-7478 PUBLISHED CVSS 7.5 HIGH

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

EPSS 4.60% · 89.2th percentile

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
4.60%
89.2th percentile

Affected Products

VendorProductVersions
openvpnopenvpn2.4.1, 2.3.12, 2.3.13
OpenVPN Technologies, Incopenvpn2.3.12 and newer

Timeline

References

Open in Interactive Console →