Описание
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:openvpn:openvpn:2.3.12:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.3.13:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.3.14:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.1:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03313
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-617
CWE-20
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 8 лет назад
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
CVSS3: 7.5
debian
около 8 лет назад
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Deni ...
CVSS3: 7.5
github
около 3 лет назад
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
EPSS
Процентиль: 87%
0.03313
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-617
CWE-20