The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Aug 2025 01:00:00 +0900

Type Values Removed Values Added
First Time appeared Openvpn openvpn 3
CPEs cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:* cpe:2.3:a:openvpn:openvpn_3:*:*:*:*:*:*:*:*
Vendors & Products Openvpn openvpn
Openvpn openvpn 3

Thu, 21 Aug 2025 23:30:00 +0900

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn
CPEs cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:*
Vendors & Products Openvpn
Openvpn openvpn

Mon, 28 Oct 2024 09:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2024-10-28T00:05:34.713Z

Reserved: 2023-11-21T20:06:31.515Z

Link: CVE-2023-6247

cve-icon Vulnrichment

Updated: 2024-08-02T08:21:18.110Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-29T01:42:34.380

Modified: 2025-08-21T15:53:11.440

Link: CVE-2023-6247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses