CVE-2017-7478
high · 7.5OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
7.5
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2017-05-15
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-617CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openvpn | openvpn | 2.3.12 |
| openvpn | openvpn | 2.3.13 |
| openvpn | openvpn | 2.3.14 |
| openvpn | openvpn | 2.4.0 |
| openvpn | openvpn | 2.4.0 |
| openvpn | openvpn | 2.4.0 |
| openvpn | openvpn | 2.4.0 |
| openvpn | openvpn | 2.4.0 |
| openvpn | openvpn | 2.4.0 |
| openvpn | openvpn | 2.4.1 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/98444
- http://www.securitytracker.com/id/1038473
- https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits
- https://www.exploit-db.com/exploits/41993/
- http://www.securityfocus.com/bid/98444
- http://www.securitytracker.com/id/1038473
- https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits
- https://www.exploit-db.com/exploits/41993/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-7478