CVE-2017-7479: Openvpn

Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.

OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.

Affected products

  • Openvpn Openvpn: up to and including 2.3.14; version 2.4.0 only; version 2.4.1 only

Published 2017-05-15. Last modified 2026-06-17.