← Back

CVE-2017-7478

nvd nist
Published: May 15, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

Affected (10)

Products: Openvpn: Openvpn
1 product
Openvpn
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Openvpn
Version 2.3.12
Version 2.3.13
Version 2.3.14
Version 2.4.0
Version 2.4.0 alpha2
Version 2.4.0 beta1
Version 2.4.0 beta2
Version 2.4.0 rc1
Version 2.4.0 rc2
Version 2.4.1

References (8)

Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.