5.5

CVE-2025-13751

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenvpnOpenvpn SwEditioncommunity Version >= 2.5.0 < 2.6.17
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updatealpha1 SwEditioncommunity
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updatealpha2 SwEditioncommunity
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updatealpha3 SwEditioncommunity
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updatebeta1 SwEditioncommunity
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updatebeta2 SwEditioncommunity
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updatebeta3 SwEditioncommunity
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updaterc1 SwEditioncommunity
   MicrosoftWindows Version-
OpenvpnOpenvpn Version2.7 Updaterc2 SwEditioncommunity
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security@openvpn.net 1.3 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

CWE-775 Missing Release of File Descriptor or Handle after Effective Lifetime

The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.

CWE-841 Improper Enforcement of Behavioral Workflow

The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.