OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/kmukoo101/CVEye