CNNVD-202512-344 Information
CNNVD ID
CNNVD-202512-344
Related CVE
- CNNVD Published: 2025-12-03
Description (Chinese)
OpenVPN是美国OpenVPN公司的一个用于创建虚拟专用网络(VPN)加密通道的软件包,它使用OpenSSL库来加密数据与控制信息,并允许创建的VPN使用公开密钥、电子证书或者用户名/密码来进行身份验证。 OpenVPN 2.6.0版本至2.7_rc1版本存在安全漏洞,该漏洞源于源IP地址验证不当,可能导致攻击者从不同IP地址打开会话并导致拒绝服务。
Description (English)
OpenVPN is a software package for the creation of a virtual private network (VPN) encryption channel at OpenVPN, United States, which uses the OpenSSL library to encrypt data and control information and allows the created VPN to use public keys, electronic certificates or username/cipher for identification. OpenVPN version 2.6.0 to 2.7 rc1 contains a security loophole, which stems from the inappropriate validation of the source IP address, which may lead the attackers to open a session from different IP addresses and lead to the denial of services.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
OpenVPN
Published
2025-12-03
Last Modified
2026-02-24
References
https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00151.html https://community.openvpn.net/Security%20Announcements/CVE-2025-13086 https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00152.html https://vigilance.fr/vulnerability/OpenVPN-OpenSource-no-signature-via-HMAC-Based-Protection-48803
Patch
https://community.openvpn.net/ReleaseHistory#openvpn-27_rc2-released-17-november-2025
Share on: