Openvpn Technologies Inc Openvpn vulnerabilities

6 known vulnerabilities affecting openvpn_technologies_inc/openvpn.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2017-7508HIGHCVSS 7.5vbefore 2.4.3vbefore 2.3.172017-06-27
CVE-2017-7508 [HIGH] CWE-617 CVE-2017-7508: OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when rece OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.
nvd
CVE-2017-7520HIGHCVSS 7.4vbefore 2.4.3vbefore 2.3.172017-06-27
CVE-2017-7520 [HIGH] CWE-200 CVE-2017-7520: OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.
nvd
CVE-2017-7521MEDIUMCVSS 5.9vbefore 2.4.3vbefore 2.3.172017-06-27
CVE-2017-7521 [MEDIUM] CWE-400 CVE-2017-7521: OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to me OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().
nvd
CVE-2017-7522MEDIUMCVSS 6.5vbefore 2.4.3vbefore 2.3.172017-06-27
CVE-2017-7522 [MEDIUM] CWE-20 CVE-2017-7522: OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
nvd
CVE-2017-7478HIGHCVSS 7.5PoCv2.3.12 and newer2017-05-15
CVE-2017-7478 [HIGH] CWE-617 CVE-2017-7478: OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via re OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
nvd
CVE-2017-7479MEDIUMCVSS 6.5fixed in 2.3.15fixed in 2.4.22017-05-15
CVE-2017-7479 [MEDIUM] CWE-617 CVE-2017-7479: OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
nvd