9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Description
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
AI Analysis
Heap buffer over-read vulnerability in OpenVPN due to insufficient argument validation
Basic Information
ID
CVE-2025-12106
Source
OpenVPN
Published
Dec 1, 2025 at 12:43
Modified
Dec 1, 2025 at 18:50
Affected Product
Vendor
OpenVPN
Product
OpenVPN
Version
2.7_alpha1
Affected Versions
OpenVPN OpenVPN 2.7_alpha1
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
OpenVPN
Product
OpenVPN
Version
2.7_alpha1, 2.7_rc1