CVE-2025-2704: Openvpn
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Affected products
- Openvpn Openvpn: from 2.6.1, up to and including 2.6.13
Published 2025-04-02. Last modified 2026-06-17.