Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
TheGreenBow VPN Client Windows Enterprise: versions 7.5 and 7.6.
INCIBE has coordinated the publication of a high-severity vulnerability affecting TheGreenBow VPN Client Windows Enterprise, a Virtual Private Network (VPN) client software certified for the Windows Enterprise operating system.
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:
- CVE-2025-11955: CVSS v4.0: 8.2 | CVSS AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N | CWE-299
The feature that was vulnerable has been removed in the next minor version (version 7.7). It will be properly reintroduced in the next major version.
To verify certificate revocation, it is recommended to use the CRL verification function of VPN clients.
CVE-2025-11955: incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.



