VYPR
High severity7.5NVD Advisory· Published May 15, 2017· Updated May 13, 2026

CVE-2017-7478

CVE-2017-7478

Description

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

Affected products

11
  • OpenVPN/OpenVPN11 versions
    cpe:2.3:a:openvpn:openvpn:2.3.12:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:openvpn:openvpn:2.3.12:*:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.3.13:*:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.3.14:*:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.4.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.4.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.4.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.4.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:openvpn:openvpn:2.4.1:*:*:*:*:*:*:*
    • (no CPE)range: 2.3.12 and newer

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.