HomeOpenvpnCVE-2025-12106

CVE-2025-12106

CRITICAL
9.1CVSS
Published: 2025-12-01
Updated: 2025-12-30
AI Analysis

Description

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
none
Availability
high
Weaknesses
CWE-126

Metadata

Primary Vendor
OPENVPN
Published
12/1/2025
Last Modified
12/30/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

openvpn : openvpnopenvpn : openvpnopenvpn : openvpnopenvpn : openvpnopenvpn : openvpnopenvpn : openvpnopenvpn : openvpnopenvpn : openvpn

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief