TheGreenBow Vulnerabilities and Affected Products
Vulnerabilities associated with TheGreenBow VPN Client Windows Enterprise.
Products
Clear product- android_vpn1 vulnerability
- TheGreenBow VPN Client Windows Enterprise1 vulnerability
- vpn_client_linux1 vulnerability
- vpn_client_macos1 vulnerability
- windows_enterprise_vpn1 vulnerability
- windows_standard_vpn1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-11955HIGH | Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows EnterpriseIncorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid. CWE-299Oct 27, 2025 | CVSS8.2v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |