# CVE-2025-13751

## Summary

- **CVE ID:** CVE-2025-13751
- **Severity:** LOW
- **CVSS Score:** 1.3 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/U:Clear)
- **CWE:** CWE-770, CWE-775, CWE-841
- **Published:** Dec 3, 2025
- **Last Modified:** Mar 13, 2026

## Description

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.

## Affected Products

- OpenVPN — OpenVPN (2.5.0)
- OpenVPN — OpenVPN (2.7_alpha1)

## References

- [CNA](https://community.openvpn.net/Security%20Announcements/CVE-2025-13751)
- [CNA](https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00154.html)
- [CNA](https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00153.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._