6.6 Medium
AI Score
Confidence
High
0.004 Low
EPSS
Percentile
73.1%
OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
www.debian.org/security/2017/dsa-3900
www.securityfocus.com/bid/98443
www.securitytracker.com/id/1038473
community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits