Executive brief
OpenVPN, a widely used software for creating secure private networks, is vulnerable to a flaw that can cause the service to crash. An attacker with basic user credentials could send a specially crafted authentication request that forces the server to shut down. This results in a denial of service, preventing legitimate users from connecting to the corporate network or accessing remote resources.
Technical details
A reachable assertion vulnerability (CWE-617) exists in OpenVPN when the 'external-auth' feature is enabled. Remote attackers with low privileges can exploit this by providing a malformed authentication token during the connection process. The malformed token triggers an internal assertion failure, causing the OpenVPN process to terminate unexpectedly. This vulnerability affects versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. Successful exploitation results in a complete loss of availability for the VPN service.
Affected products
- OpenVPN Inc. OpenVPN 2.6.0 through 2.6.20, 2.7_alpha1 through 2.7.4
Timeline
- 2026-07-06: advisory: NVD publication date