Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11771

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

A flaw was found in OpenVPN. A remote attacker could exploit an off-by-one buffer write vulnerability during NTLM (NT LAN Manager) proxy authentication. By sending a specially crafted NTLM response from a malicious proxy server, the attacker could cause the OpenVPN client to crash, leading to a denial of service.

Отчет

This Moderate impact flaw in OpenVPN clients allows a denial of service via an off-by-one buffer write during NTLM proxy authentication. Exploitation requires a client to connect through a malicious NTLM proxy server, which can then send a specially crafted response. The necessity of user interaction with a compromised proxy limits the overall risk.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2509516openvpn: OpenVPN: Denial of Service via crafted NTLM proxy response

EPSS

Процентиль: 30%
0.00375
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
20 дней назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 7.5
nvd
20 дней назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 7.5
debian
20 дней назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...

CVSS3: 7.5
github
20 дней назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

suse-cvrf
7 дней назад

Security update for openvpn

EPSS

Процентиль: 30%
0.00375
Низкий

5.3 Medium

CVSS3