CVE-2025-11955
Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.
Published:Oct 27, 2025
Last Modified:Apr 15, 2026
EPS:Oct 27, 2025
EPSS Score:0.00032
CVSS Score:8.2
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Windows
Microsoft
Windows
Vendor
Thegreenbow
Product
Ipsec Vpn Client
Thegreenbow
Ipsec Vpn Client
Vendor
Thegreenbow
Product
Thegreenbow Vpn Client
Thegreenbow
Thegreenbow Vpn Client
Vendor
Thegreenbow
Product
Vpn Client Linux
Thegreenbow
Vpn Client Linux
Vendor
Thegreenbow
Product
Windows Enterprise Certified Vpn
Thegreenbow
Windows Enterprise Certified Vpn
Vendor
Thegreenbow
Product
Windows Enterprise Vpn
Thegreenbow
Windows Enterprise Vpn
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
