OpenVPN: OpenVPN: Local denial of service vulnerability in interactive service agent
Published Dec 3, 2025
1.3
LOWCVSS 4.0
EPSS 0.17%
Description
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
Affected products
-
- Version 2.5.0StatusaffectedConstraints<=2.6.16
- Version 2.7_alpha1StatusaffectedConstraints<=2.7_rc2
- Version
- ≥ 2.5.0 · < 2.6.17
- 2.7
- 2.7
- 2.7
- 2.7
- 2.7
- 2.7
- 2.7
- 2.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated Low for Red Hat. The flaw affects the interactive service agent in OpenVPN on Windows, allowing a local authenticated user to trigger a denial of service. Red Hat's OpenVPN packages are typically deployed on Linux systems and do not include the Windows-specific interactive service agent, therefore No Red Hat products or offerings are affected by this vulnerability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/U:Clear
1 other source (NVD) ▾
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 3, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.17% (0.00171) | 5.76th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.15% (0.00151) | 4.62th | v5 (v2026.06.15) |
| Dec 4, 2025 | 0.01% (0.00013) | 1.49th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2025-13751 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418624 Issue Tracking
- https://community.openvpn.net/Security%20Announcements/CVE-2025-13751 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-13751
- https://www.cve.org/CVERecord?id=CVE-2025-13751
- https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00153.html release-notesMailing ListRelease Notes
- https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00154.html release-notesMailing ListRelease Notes
- https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00154.htmlhttps://
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-13751 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2418624 | Issue Tracking | |
| https://community.openvpn.net/Security%20Announcements/CVE-2025-13751 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-13751 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-13751 | ||
| https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00153.html | release-notesMailing ListRelease Notes | |
| https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00154.html | release-notesMailing ListRelease Notes | |
| https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00154.htmlhttps:// |
Change history (0)
No recorded changes yet.