TheGreenBow VPN Client
cpe:2.3:a:thegreenbow:windows_enterprise_vpn:*:*:*:*:*:*:*
- 7.5
- 7.6
A vulnerability exists in TheGreenBow VPN Client for Windows Enterprise, specifically in versions 7.5 and 7.6, due to incorrect validation of OCSP certificates. During the IKEv2 authentication process, the VPN client can establish a tunnel even if it fails to receive a valid OCSP response or if the OCSP response's signature is invalid.
This vulnerability could lead to unauthorized VPN tunnel establishment, allowing potentially unverified connections to be made.
Users can upgrade to TheGreenBow VPN Client version 7.7, where this vulnerability has been addressed. For immediate needs, it is recommended to use the CRL verification function available in VPN clients.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.