{"id":"CVE-2025-11955","title":"Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6","summary":"Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if…","severity":"none","cwe":["CWE-299"],"published":"2025-10-27","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11955","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/incorrect-validation-ocsp-certificates-thegreenbow-vpn-client-windows","label":"cve-coordination@incibe.es"},{"url":"https://www.thegreenbow.com/en/support/security-alerts/","label":"cve-coordination@incibe.es"}],"tags":["nvd"],"epss":0.00211,"epssPercentile":0.10403,"ingestedAt":"2026-10-08T11:31:27.630Z","slug":"CVE-2025-11955","body":"## Overview\n\nIncorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}