CVE-2017-7478
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 14%
from disclosure to weapon0 days
Published on NVDMay 15
1st PoCMay 11
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
Affected products
OpenVPN Technologies, Inc · openvpnpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/41993cve_referencewww.exploit-db.com/exploits/41993/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.