HomeOpenvpnCVE-2023-46849

CVE-2023-46849

HIGH
7.5CVSS
Published: 2023-11-11
Updated: 2025-06-11
AI Analysis

Description

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
high
Weaknesses
CWE-369CWE-369

Metadata

Primary Vendor
OPENVPN
Published
11/11/2023
Last Modified
6/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

openvpn : openvpnopenvpn : openvpn_access_serveropenvpn : openvpn_access_serveropenvpn : openvpn_access_serverdebian : debian_linuxfedoraproject : fedora

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief