Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.
History

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Thegreenbow
Thegreenbow ipsec Vpn Client
Thegreenbow thegreenbow Vpn Client
Thegreenbow vpn Client Linux
Thegreenbow windows Enterprise Certified Vpn
Thegreenbow windows Enterprise Vpn
Vendors & Products Microsoft
Microsoft windows
Thegreenbow
Thegreenbow ipsec Vpn Client
Thegreenbow thegreenbow Vpn Client
Thegreenbow vpn Client Linux
Thegreenbow windows Enterprise Certified Vpn
Thegreenbow windows Enterprise Vpn

Mon, 27 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 11:45:00 +0000

Type Values Removed Values Added
Description Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.
Title Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
Weaknesses CWE-299
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-10-27T11:30:24.102Z

Updated: 2025-10-27T13:19:15.842Z

Reserved: 2025-10-20T11:57:59.432Z

Link: CVE-2025-11955

cve-icon Vulnrichment

Updated: 2025-10-27T13:19:09.379Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-27T12:15:32.670

Modified: 2025-10-27T13:19:49.063

Link: CVE-2025-11955

cve-icon Redhat

No data.