← Vulnerability feed

Vulnerability record · CVE-2017-7478 · published 15 May 2017

CVE-2017-7478: Openvpn improper input validation vulnerability

Openvpn · Openvpn

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

7.5 CVSS 3.0 High EPSS 14% · top 3.6% CWE-617 · CWE-617CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7478 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27903Openvpn unrestricted file upload vulnerabilityOpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in …EPSS 8.9%9.8CVE-2023-46850Openvpn use after free vulnerabilityUse after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buff…EPSS 2.0%9.8CVE-2022-0547Openvpn improper authentication vulnerabilityOpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of def…EPSS 3.6%9.8CVE-2017-12166Openvpn out-of-bounds write vulnerabilityOpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting …EPSS 3.6%9.1CVE-2025-12106Openvpn vulnerabilityInsufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addressesEPSS 0.56%9.1CVE-2024-5594Openvpn vulnerabilityOpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary d…EPSS 0.84%9.1CVE-2018-7544Openvpn vulnerabilityA cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without…EPSS 1.8%9.0CVE-2006-1629Openvpn vulnerabilityOpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment var…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2017-7478), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.