CVE-2025-2704
EUVD-2025-957102.04.2025, 21:15
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phaseEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openvpn | openvpn | 2.6.1 ≤ 𝑥 ≤ 2.6.13 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| openvpn |
| ||||||||||||
| openvpn-auth-pam-plugin |
| ||||||||||||
| openvpn-dco |
| ||||||||||||
| openvpn-dco-devel |
| ||||||||||||
| openvpn-devel |
|
Common Weakness Enumeration