CVE-2017-7508: High severity OpenVPN OpenVPN vulnerability
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7508?
CVE-2017-7508 is classified as a medium severity vulnerability due to its potential for causing remote denial-of-service.
How do I fix CVE-2017-7508?
To resolve CVE-2017-7508, upgrade to OpenVPN version 2.4.3 or later if using version 2.4, or version 2.3.17 or later if using version 2.3.
What versions of OpenVPN are affected by CVE-2017-7508?
OpenVPN versions before 2.4.3 and before 2.3.17, including various beta and release candidate versions, are affected by CVE-2017-7508.
What type of attack does CVE-2017-7508 enable?
CVE-2017-7508 enables a remote denial-of-service attack through the receipt of malformed IPv6 packets.
Is my OpenVPN configuration safe if I am using a vulnerable version identified in CVE-2017-7508?
No, using a vulnerable version identified in CVE-2017-7508 puts your OpenVPN configuration at risk of denial-of-service attacks, so it is advised to update immediately.