OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openvpn | Aug 22, 2024 | Jul 8, 2024 |
| Debian | — | Upgrade openvpn | May 15, 2025 | Jul 8, 2024 |
| Freebsd | — | Upgrade openvpn | Dec 10, 2025 | Jun 20, 2024 |
| Suse | — | Upgrade openvpn-dcoUpgrade openvpnUpgrade openvpn-auth-pam-pluginUpgrade openvpn-dco-develUpgrade openvpn-develUpgrade openvpn-down-root-plugin | Dec 5, 2025 | Oct 1, 2024 |
| Ubuntu | — | Upgrade openvpn | Jul 3, 2024 | Jul 2, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub