OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Metrics
Affected Vendors & Products
References
History
Thu, 23 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 24 May 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openvpn
Openvpn openvpn |
|
| CPEs | cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:* | |
| Vendors & Products |
Openvpn
Openvpn openvpn |
Mon, 07 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 03 Apr 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 02 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase | |
| Weaknesses | CWE-754 | |
| References |
|
Status: PUBLISHED
Assigner: OpenVPN
Published: 2025-04-02T21:00:58.582Z
Updated: 2025-10-23T10:53:34.373Z
Reserved: 2025-03-24T10:26:42.493Z
Link: CVE-2025-2704
Updated: 2025-04-03T00:11:05.289Z
Status : Modified
Published: 2025-04-02T21:15:32.943
Modified: 2025-10-23T11:15:31.207
Link: CVE-2025-2704
No data.