← Back

CVE-2025-13086

nvd nist
Published: Dec 3, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.6
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@openvpn.net (Secondary)

Description

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client

Affected (8)

Products: Openvpn: Openvpn
1 product
Openvpn
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Openvpn
From 2.6.0 to 2.6.16
Version 2.7 alpha1
Version 2.7 alpha2
Version 2.7 alpha3
Version 2.7 beta1
Version 2.7 beta2
Version 2.7 beta3
Version 2.7 rc1

References (3)

Timeline

No history available yet.