---
id: CVE-2025-11955
title: >-
  Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN,
  versions 7.5 and 7.6
summary: >-
  Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN,
  versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled
  VPN client establishes the tunnel even if it does not receive an OCSP response
  or if…
severity: none
cwe:
  - CWE-299
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11955'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/incorrect-validation-ocsp-certificates-thegreenbow-vpn-client-windows
    label: cve-coordination@incibe.es
  - url: 'https://www.thegreenbow.com/en/support/security-alerts/'
    label: cve-coordination@incibe.es
tags:
  - nvd
epss: 0.00211
epssPercentile: 0.10403
ingestedAt: '2026-10-08T11:31:27.630Z'
---

## Overview

Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
