Skip to main content

Go to Calendar     Go to Press Room     Go to Newsletters subscription

  • INCIBE
    • Your Help in Cybersecurity
      • FAQ
    • Training
    • Cibercooperantes Program
    • Press Room
    • Corporate information
      • What is INCIBE
          1. Organisation chart
          2. Internal regulations
      • What we do
      • How do we operate
      • Who we work with
          1. European projects participation
          2. Memberships
          3. Network of excellence on cybersecurity R&D&i
          4. Companies
      • Contracting Organisation Profile
      • Calendar
  • INCIBE-CERT
    • Early Warning
      • Security Advisories
      • ICS Advisories
      • Vulnerabilities
          1. CNA
          2. CVE assignment and publication
          3. Coordinated CVEs
          4. Participating CNAs
    • Blog
    • Publications
      • Cybersecurity Highlights
      • Guides
      • Webinars
      • Segmented
    • Incidents
      • Incident responses
    • Services
    • About us
      • What is INCIBE-CERT
      • PGP Public keys
      • TLP
      • Vulnerability disclosure policy
      • RFC 2350
  • CITIZENS
    • We help you
      • Tu Ayuda en Ciberseguridad
      • Reporte de fraude
    • Security tools
    • Temáticas
  • MINORS
    • Educators
    • Families
      • Parental Mediation
      • Cybersecurity
    • Youth
    • Hotline
  • Companies
    • We help you
      • Tu Ayuda en Ciberseguridad
    • TemáTICas
  • EVENTS
    • SID
    • Cybersecurity Summer BootCamp
    • ENISE
    • CyberCamp
  • DIGITAL SPAIN 2026
    • Cybersecurity Entrepreneurship
    • NCC-ES INCIBE
    • Internationalization
      • New Markets
      • Exterior Visibility
      • Foreign Investment
 
Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT
  • INCIBE
    •  
    • Your Help in Cybersecurity
      •  
      • FAQ
    • Training
    • Cibercooperantes Program
    • Press Room
    • Corporate information
      •  
      • What is INCIBE
        •  
          1. Organisation chart
          2. Internal regulations
      • What we do
      • How do we operate
      • Who we work with
        •  
          1. European projects participation
          2. Memberships
          3. Network of excellence on cybersecurity R&D&i
          4. Companies
      • Contracting Organisation Profile
      • Calendar
  • INCIBE-CERT
    •  
    • Early Warning
      •  
      • Security Advisories
      • ICS Advisories
      • Vulnerabilities
        •  
          1. CNA
          2. CVE assignment and publication
          3. Coordinated CVEs
          4. Participating CNAs
    • Blog
    • Publications
      •  
      • Cybersecurity Highlights
      • Guides
      • Webinars
      • Segmented
    • Incidents
      •  
      • Incident responses
    • Services
    • About us
      •  
      • What is INCIBE-CERT
      • PGP Public keys
      • TLP
      • Vulnerability disclosure policy
      • RFC 2350
  • CITIZENS
    •  
    • We help you
      •  
      • Tu Ayuda en Ciberseguridad
      • Reporte de fraude
    • Security tools
    • Temáticas
  • MINORS
    •  
    • Educators
    • Families
      •  
      • Parental Mediation
      • Cybersecurity
    • Youth
    • Hotline
  • Companies
    •  
    • We help you
      •  
      • Tu Ayuda en Ciberseguridad
    • TemáTICas
  • EVENTS
    •  
    • SID
    • Cybersecurity Summer BootCamp
    • ENISE
    • CyberCamp
  • DIGITAL SPAIN 2026
    •  
    • Cybersecurity Entrepreneurship
    • NCC-ES INCIBE
    • Internationalization
      •  
      • New Markets
      • Exterior Visibility
      • Foreign Investment

Go to Calendar     Go to Press Room     Go to Newsletters subscription

Search

  1. Home
  2. INCIBE-CERT
  3. Early warning
  4. Vulnerabilities
  5. CVE-2025-15497

CVE-2025-15497

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
30/01/2026
Last modified:
30/01/2026

Description

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service

Impact

Vector 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U CVSS v4.0 Severity and Metrics:

Base Score: 3.80 LOW
Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U

Attack Vector (AV): Network
Attack Complexity (AC): High
Attack Requirements (AT): None
Privileges Required (PR): Low
User Interaction (UI): None
Confidentiality (VC): None
Integrity (VI): None
Availability (VA): High
Confidentiality (SC): None
Integrity (SI): None
Availability (SA): High
Exploit Maturity (E): Unreported

Base Score 4.0
3.80
Severity 4.0
LOW

References to Advisories, Solutions, and Tools

  • https://community.openvpn.net/Security%20Announcements/CVE-2025-15497
  • https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00156.html
INCIBE-CERT

Newsletter subscription

Nipo: 094-20-022-9

Follow us:  Link to INCIBE-CERT's Twitter Link to INCIBE-CERT's Linkedin Link to INCIBE-CERT's YouTube account

  • Contact
  • Personal Data Protection Policy
  • Legal notice
  • Configure cookies
  • Cookies policy
  • Site Map
  • Contracting Organisation Profile

Funded by the European Union - Next Generation EU

 

Government of Spain. Ministry for digital transformation and public service. Secretary of state for for Telecommunications and Digital Infrastructures

Recovery, Transformation and Resilience Plan

 

Certificado de Conformidad con el Esquema Nacional de Seguridad (ENS) RD 311/2022
Seguridad de la Información, ISO/IEC 27001
Sistema de Gestión de la Calidad, ISO 9001

Nipo: 094-20-027-6

INCIBE on Twitter INCIBE on Instagram INCIBE on Linkedin INCIBE on Facebook INCIBE on YouTube

×

imagen ampliada

Go top