CVE-2025-13086
EUVD-2025-20110203.12.2025, 20:16
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating clientEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openvpn | openvpn | 2.6.0 ≤ 𝑥 < 2.6.16 |
| openvpn | openvpn | 2.7:alpha1 |
| openvpn | openvpn | 2.7:alpha2 |
| openvpn | openvpn | 2.7:alpha3 |
| openvpn | openvpn | 2.7:beta1 |
| openvpn | openvpn | 2.7:beta2 |
| openvpn | openvpn | 2.7:beta3 |
| openvpn | openvpn | 2.7:rc1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases