← All CVEs

CVE-2017-7478

high · 7.5

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

7.5
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2017-05-15
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-617CWE-20

Affected products

VendorProductAffected versions
openvpnopenvpn2.3.12
openvpnopenvpn2.3.13
openvpnopenvpn2.3.14
openvpnopenvpn2.4.0
openvpnopenvpn2.4.0
openvpnopenvpn2.4.0
openvpnopenvpn2.4.0
openvpnopenvpn2.4.0
openvpnopenvpn2.4.0
openvpnopenvpn2.4.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-7478