CVE-2014-8104

UnknownEPSS 3.48%

Last modified

CVE-2014-8104 is a vulnerability of currently unknown severity. OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.. EPSS estimates a 3.48% chance of exploitation in the next 30 days.

Description

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

Metrics

EPSS Probability
3.48%

87.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
MageiaMageia4.0
DebianDebian Linux7.0
DebianDebian Linux8.0
OpensuseOpensuse12.3
OpensuseOpensuse13.1
OpensuseOpensuse13.2
OpenvpnOpenvpn2.0.1_rc1
OpenvpnOpenvpn2.0.1_rc2
OpenvpnOpenvpn2.0.1_rc3
OpenvpnOpenvpn2.0.1_rc4
OpenvpnOpenvpn2.0.1_rc5
OpenvpnOpenvpn2.0.1_rc6
OpenvpnOpenvpn2.0.1_rc7
OpenvpnOpenvpn2.0.2_rc1
OpenvpnOpenvpn2.0.3_rc1
OpenvpnOpenvpn2.0.4
OpenvpnOpenvpn2.0.6_rc1
OpenvpnOpenvpn2.0.9
OpenvpnOpenvpn2.0_rc1
OpenvpnOpenvpn2.0_rc2
OpenvpnOpenvpn2.0_rc3
OpenvpnOpenvpn2.0_rc4
OpenvpnOpenvpn2.0_rc5
OpenvpnOpenvpn2.0_rc6
OpenvpnOpenvpn2.0_rc7
OpenvpnOpenvpn2.0_rc8
OpenvpnOpenvpn2.0_rc9
OpenvpnOpenvpn2.0_rc10
OpenvpnOpenvpn2.0_rc11
OpenvpnOpenvpn2.0_rc12
OpenvpnOpenvpn2.0_rc13
OpenvpnOpenvpn2.0_rc14
OpenvpnOpenvpn2.0_rc15
OpenvpnOpenvpn2.0_rc16
OpenvpnOpenvpn2.0_rc17
OpenvpnOpenvpn2.0_rc18
OpenvpnOpenvpn2.0_rc19
OpenvpnOpenvpn2.0_rc20
OpenvpnOpenvpn2.0_rc21
OpenvpnOpenvpn2.0_test1
OpenvpnOpenvpn2.0_test2
OpenvpnOpenvpn2.0_test3
OpenvpnOpenvpn2.0_test4
OpenvpnOpenvpn2.0_test5
OpenvpnOpenvpn2.0_test6
OpenvpnOpenvpn2.0_test7
OpenvpnOpenvpn2.0_test8
OpenvpnOpenvpn2.0_test9
OpenvpnOpenvpn2.0_test10
OpenvpnOpenvpn2.0_test11

Showing 50 of 96 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-8104?
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
How severe is CVE-2014-8104?
Severity scoring for CVE-2014-8104 is pending analysis. The EPSS model estimates a 3.48% probability of exploitation in the next 30 days.
How do I fix CVE-2014-8104?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-8104?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST