Impact
The vulnerability is caused by retransmissions of ACK packet IDs in OpenVPN versions 2.6.22 and 2.7.6. Crafted ACK packets trigger a timeout integer overflow that forces the VPN process to fail, resulting in a denial of service for remote users. The flaw allows unauthenticated attackers to disrupt VPN services without authentication, impacting network availability.
Affected Systems
OpenVPN customers running software versions 2.6.22 or 2.7.6 are affected. These versions are commonly deployed in corporate and remote‑access environments.
Risk and Exploitability
The CVSS score of 8.7 categorises this as a high‑severity flaw. No EPSS score is available, and the vulnerability is not yet listed in CISA KEV, but the type of exploit—remote crafted packet injection—suggests a realistic threat if network traffic can be manipulated. An attacker can send malformed ACK packets from any location on the network to trigger the integer overflow and cause a service crash.
OpenCVE Enrichment