CVE-2017-7478: Openvpn
High severity, CVSS 7.5. EPSS: 13.8% chance of exploitation in the next 30 days.
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
Affected products
- Openvpn Openvpn: version 2.3.12 only; version 2.3.13 only; version 2.3.14 only; version 2.4.0 only; version 2.4.1 only
Published 2017-05-15. Last modified 2026-06-17.