#VU118819 Insufficient verification of data authenticity in OpenVPN Server - CVE-2025-13086

 

#VU118819 Insufficient verification of data authenticity in OpenVPN Server - CVE-2025-13086

Published: November 27, 2025


Vulnerability identifier: #VU118819
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-13086
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
OpenVPN Server
Software vendor:
OpenVPN

Description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper handling of HMAC verification checks during the three way handshake. A remote attacker can bypass source IP address validation and connect to the server from an IP address that did not initiate the initial connection. 


Remediation

Install updates from vendor's website.

External links