The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn openvpn 3
CPEs cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:* cpe:2.3:a:openvpn:openvpn_3:*:*:*:*:*:*:*:*
Vendors & Products Openvpn openvpn
Openvpn openvpn 3

Thu, 21 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn
CPEs cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:*
Vendors & Products Openvpn
Openvpn openvpn

Mon, 28 Oct 2024 00:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2024-10-28T00:05:34.713Z

Reserved: 2023-11-21T20:06:31.515Z

Link: CVE-2023-6247

cve-icon Vulnrichment

Updated: 2024-08-02T08:21:18.110Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-29T01:42:34.380

Modified: 2025-08-21T15:53:11.440

Link: CVE-2023-6247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.