OpenVPN 在 2.6.22 及 2.7.6 及之前版本中,ACK 数据包 ID 的重传机制允许远程未认证的攻击者通过构造特定输入以触发超时整数溢出,从而导致拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84226 | 8.5 HIGH | OpenVPN 2.5.0-2.7.6 Windows 本地二进制植入 |
| CVE-2026-84256 | 7.7 HIGH | OpenVPN 2.1至2.7 Windows参数解析远程命令执行 |
| CVE-2026-78221 | 5.9 MEDIUM | OpenVPN 2.7.6 Windows版缓冲区溢出漏洞 |
| CVE-2026-78043 | 5.6 MEDIUM | OpenVPN 2.7.6 Windows服务本地配置路径绕过 |
| CVE-2026-81830 | 5.6 MEDIUM | OpenVPN 2.4.0-2.6.22 本地服务配置目录约束绕过 |
| CVE-2026-81738 | 2.3 LOW | OpenVPN 2.5.0-2.7.6 Windows版越界写漏洞 |
| CVE-2026-82312 | 1.8 LOW | OpenVPN 2.7.6 Windows IPC空描述符拒绝服务 |
No comments yet