CVE-2017-7478: Openvpn

High severity, CVSS 7.5. EPSS: 13.8% chance of exploitation in the next 30 days.

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

Affected products

  • Openvpn Openvpn: version 2.3.12 only; version 2.3.13 only; version 2.3.14 only; version 2.4.0 only; version 2.4.1 only

Published 2017-05-15. Last modified 2026-06-17.