TheGreenBow Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with TheGreenBow products.
Products
- android_vpn1 vulnerability
- TheGreenBow VPN Client Windows Enterprise1 vulnerability
- vpn_client_linux1 vulnerability
- vpn_client_macos1 vulnerability
- windows_enterprise_vpn1 vulnerability
- windows_standard_vpn1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-11955HIGH | Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows EnterpriseIncorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid. CWE-299Oct 27, 2025 | CVSS8.2v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45750HIGH | An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and older) allows a remote attacker to execute arbitrary code via the IKEv2 Authentication phase, it accepts malformed ECDSA signatures and establishes the tunnel. CWE-287Sep 25, 2024 | CVSS7.3v3.1 | EPSS0.505% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |