ALT-PU-2025-14191-2
Closed vulnerabilities
Published: 2025-04-30
Modified: 2025-09-22
Modified: 2025-09-22
BDU:2025-05051
Уязвимость функции TLS-crypt-v2 сервера программного обеспечения OpenVPN, позволяющая нарушителю вызвать отказ в обслуживании
Severity: LOW (3.7)
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity: LOW (2.6)
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P
References:
Published: 2025-04-02
Modified: 2025-10-23
Modified: 2025-10-23
CVE-2025-2704
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References: