Vulnerability Description
The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openvpn | Openvpn 3 | < 3.8.4 |
Related Weaknesses (CWE)
References
- https://community.openvpn.net/openvpn/wiki/CVE-2023-6247PatchVendor Advisory
- https://community.openvpn.net/openvpn/wiki/CVE-2023-6247PatchVendor Advisory
FAQ
What is CVE-2023-6247?
CVE-2023-6247 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.
How severe is CVE-2023-6247?
CVE-2023-6247 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6247?
Check the references section above for vendor advisories and patch information. Affected products include: Openvpn Openvpn 3.