nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-11955 CVE-2025-11955
HIGH
Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
Record summary
CVE-2025-11955 has a selected CVSS score of 8.2 (high).
Description
Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
TheGreenBow VPN Client Windows EnterpriseBrowse TheGreenBow / TheGreenBow VPN Client Windows EnterpriseDefault status: unaffected | CVE List | 7.5 | affected |
| 7.6 | affected |
References
3incibe.es
https://www.incibe.es/en/incibe-cert/notices/aviso/incorrect-validation-ocsp-certificates-thegreenbow-vpn-client-windows thegreenbow.comVendor advisorypatch
https://www.thegreenbow.com/en/support/security-alerts