CVE-2025-13751 Details
Description
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
A denial-of-service vulnerability has been identified in OpenVPN versions 2.5.0 through 2.7_rc2 on Windows. The issue allows a local authenticated user to connect to the interactive service agent and trigger an error that causes a local denial-of-service condition. After the error occurs, OpenVPN connections will fail until the service is restarted or the system is rebooted.
Users can upgrade to OpenVPN 2.7_rc3, which addresses this vulnerability. The source code and Windows installers are available on the OpenVPN community downloads page. Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE can be obtained from the official OpenVPN community repositories.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.openvpn.net/Security%20Announcements/CVE-2025-13751 | [email protected] | Vendor Advisory |
| https://www.mail-archive.com/[email protected]/msg00153.html | [email protected] | Mailing ListRelease Notes |
| https://www.mail-archive.com/[email protected]/msg00154.html | [email protected] | Mailing ListRelease Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
| CWE-775 | Missing Release of File Descriptor or Handle after Effective Lifetime | [email protected] |
| CWE-841 | Improper Enforcement of Behavioral Workflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openvpn openvpn | >= 2.5.0, < 2.6.17 2.7 alpha1 2.7 alpha2 2.7 alpha3 2.7 beta1 2.7 beta2 2.7 beta3 2.7 rc1 2.7 rc2 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 30, 2026 | Initial Analysis | [email protected] |
| Dec 12, 2025 | CVE Modified | [email protected] |
| Dec 3, 2025 | New CVE Received | [email protected] |