OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.
📦
openvpn
Vendor: openvpn
Actively Exploited
0
CISA KEV List
PoC / Exploits
2
Code Available
Total RCEs
6
Remote Access
Total CVEs
206
Total Indexed
Avg. EPSS
2.83%
Exploit Prob.
Security Vulnerability Index
Page 5 / 21
5.0
CVSS
Severity: MEDIUM
5.0
CVSS
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.
Severity: MEDIUM