What the vulnerability does

01Description

OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.

Key dates

02Disclosure timeline

May 15, 2017 CVE published
August 5, 2024 Record updated