OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Metrics
Affected Vendors & Products
References
History
Mon, 07 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 03 Apr 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 02 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase | |
Weaknesses | CWE-754 | |
References |
|

Status: PUBLISHED
Assigner: OpenVPN
Published: 2025-04-02T21:00:58.582Z
Updated: 2025-04-07T17:23:59.009Z
Reserved: 2025-03-24T10:26:42.493Z
Link: CVE-2025-2704

Updated: 2025-04-03T00:11:05.289Z

Status : Awaiting Analysis
Published: 2025-04-02T21:15:32.943
Modified: 2025-04-07T18:15:45.560
Link: CVE-2025-2704

No data.