Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8cw5-pxrw-vqhc

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.2

Описание

Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.

Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.

EPSS

Процентиль: 14%
0.00047
Низкий

8.2 High

CVSS4

Дефекты

CWE-299

Связанные уязвимости

nvd
3 месяца назад

Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.

EPSS

Процентиль: 14%
0.00047
Низкий

8.2 High

CVSS4

Дефекты

CWE-299