CPE
OpenVPN versions 2.6.22 and 2.7.6 and earlier contain a vulnerability in the reliability layer that can be triggered by unbounded TLS timeouts and acknowledgments for non-outstanding packets, potentially leading to denial-of-service.