CyberRota Analysis
AI-GeneratedOpenVPN versions 2.6.0 to 2.6.20 and 2.7_alpha1 to 2.7.4 are vulnerable due to an incomplete guard that permits remote authenticated peers to exploit a use-after-free condition during TLS session promotion. This vulnerability may result in denial of service or memory leakage, impacting the confidentiality and availability of the affected systems. Organizations using these OpenVPN versions should prioritize patching to mitigate potential risks associated with this flaw.
Original NVD Description
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
Related CVEs
Other vulnerabilities affecting the same vendor(s)