Vulnerability Description
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openvpn | Openvpn | >= 2.6.1, <= 2.6.13 |
Related Weaknesses (CWE)
References
- https://community.openvpn.net/openvpn/wiki/CVE-2025-2704Broken Link
- https://www.mail-archive.com/[email protected]/msg00142.htm
- http://www.openwall.com/lists/oss-security/2025/04/02/5Mailing List
FAQ
What is CVE-2025-2704?
CVE-2025-2704 is a vulnerability with a CVSS score of 7.5 (HIGH). OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
How severe is CVE-2025-2704?
CVE-2025-2704 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2704?
Check the references section above for vendor advisories and patch information. Affected products include: Openvpn Openvpn.