OpenVPN
cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*
- >= 2.6.0, <= 2.6.19
- >= 2.7_alpha1, <= 2.7.1
A denial-of-service vulnerability has been identified in OpenVPN versions 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1. The issue arises from improper validation of packet length during the tls-crypt-v2 key extraction process, allowing authenticated attackers to trigger a fatal assertion and cause a crash by sending a specially crafted packet.
Exploitation of this vulnerability leads to a fatal assertion failure, causing a crash and denial-of-service condition on the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.