CVE-2017-7478
Estado: ModificadaAlta (7.5)—💥 Exploit
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 14%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · OpenVPN 2.4.0 - Denial of Service (11/5/2017)
Tecnologías afectadas (1)
CWE
- CWE-617
- CWE-20
Referencias
- http://www.securityfocus.com/bid/98444
- http://www.securitytracker.com/id/1038473
- https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits
- https://www.exploit-db.com/exploits/41993/
- http://www.securityfocus.com/bid/98444
- http://www.securitytracker.com/id/1038473
- https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits
- https://www.exploit-db.com/exploits/41993/
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-7478",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "OpenVPN Technologies, Inc",
"product": "openvpn",
"versions": [
{
"status": "affected",
"version": "2.3.12 and newer"
}
]
}
]
}
],
"published": "2017-05-15T18:29:00.293",
"references": [
{
"url": "http://www.securityfocus.com/bid/98444",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id/1038473",
"source": "secalert@redhat.com"
},
{
"url": "https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://www.exploit-db.com/exploits/41993/",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/98444",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1038473",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://community.openvpn.net/openvpn/wiki/QuarkslabAndCryptographyEngineerAudits",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/41993/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-617"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2."
},
{
"lang": "es",
"value": "OpenVPN versión 2.3.12 y más recientes, son vulnerables a la Denegación de Servicio no autenticada del servidor por medio de un paquete de control grande recibido. Tenga en cuenta que este problema se corrige en versiones 2.3.15 y 2.4.2."
}
],
"lastModified": "2026-06-17T01:24:25.720",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.3.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "288EE3C5-C915-4273-B1F1-D53BC028C990"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.3.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A21C5FE2-2FF7-481F-B128-976EBA563208"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.3.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF068FA2-03A0-4C7F-97B1-9CB5A49E9E1B"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84F5C67A-34A4-4C7E-BCA9-AF3E5FC70AF6"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.4.0:alpha2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A857CA88-60B0-4D34-87B6-770B67981501"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.4.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B42297EE-B347-4BD8-A657-BDF0AA010C06"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.4.0:beta2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C7A56E8-09C8-4DB2-9244-9E5E2BEC1821"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.4.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41ACD637-EF6B-40E4-BDE6-0EE7D6AEBAD4"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.4.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A4150AD-3F46-487D-BCF8-79D0AE2A092D"
},
{
"criteria": "cpe:2.3:a:openvpn:openvpn:2.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7F7663E-3EB5-44F4-B7DE-294A549A12BE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}