7.5

CVE-2025-13086

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openvpn ≫ Openvpn SwEdition community Version >= 2.6.0 < 2.6.16
Openvpn ≫ Openvpn Version 2.7 Update alpha1 SwEdition community
Openvpn ≫ Openvpn Version 2.7 Update alpha2 SwEdition community
Openvpn ≫ Openvpn Version 2.7 Update alpha3 SwEdition community
Openvpn ≫ Openvpn Version 2.7 Update beta1 SwEdition community
Openvpn ≫ Openvpn Version 2.7 Update beta2 SwEdition community
Openvpn ≫ Openvpn Version 2.7 Update beta3 SwEdition community
Openvpn ≫ Openvpn Version 2.7 Update rc1 SwEdition community
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.466
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@openvpn.net 4.6 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-940 Improper Verification of Source of a Communication Channel

The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00152.html
Mailing List
Release Notes
https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00151.html
Mailing List
Release Notes
https://community.openvpn.net/Security%20Announcements/CVE-2025-13086
Vendor Advisory