CVE-2025-2704: - OpenVPN 2.6.1 through 2.6.13 with possible DoS
Last updated 3 April 2025
Other sources
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2704?
CVE-2025-2704 is classified as a denial of service vulnerability affecting OpenVPN versions 2.6.1 through 2.6.13.
How do I fix CVE-2025-2704?
Fixing CVE-2025-2704 involves upgrading OpenVPN to version 2.6.14 or later.
What is the impact of CVE-2025-2704?
The impact of CVE-2025-2704 allows remote attackers to disrupt OpenVPN server operations through packet manipulation.
Who is affected by CVE-2025-2704?
CVE-2025-2704 affects users running OpenVPN versions 2.6.1 through 2.6.13 in server mode with TLS-crypt-v2.
When was CVE-2025-2704 disclosed?
CVE-2025-2704 was disclosed as a vulnerability affecting certain versions of OpenVPN released prior to the fix in 2025.