CVE-2019-14899
published 2019-12-11CVE-2019-14899: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a…
PriorityP336high7.4CVSS 3.1
AVAACLPRLUIRSUCHIHAH
EPSS
0.84%
54.0th percentile
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_13.6_and_ipados | — | — |
| apple | ipados | < 13.6 | 13.6 |
| apple | iphone_os | < 13.6 | 13.6 |
| apple | mac_os_x | < 10.15.6 | 10.15.6 |
| apple | macos | — | — |
| apple | macos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004 | — | — |
| apple | tvos | < 13.4.8 | 13.4.8 |
| apple | tvos | — | — |
| red_hat | vpn | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.4HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.9MEDIUMAV:A/AC:M/Au:S/C:P/I:P/A:P
osv7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-14899: tvOS 13.4.8
vendor_apple·2020-07-15·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899: tvOS 13.4.8
Apple Security Update: About the security content of tvOS 13.4.8
Product: tvOS
Version: 13.4.8
CVE: CVE-2019-14899
Component: Kernel
Impact: An attacker in a privileged network position may be able to inject into active connections within a VPN tunnel
Description: A routing issue was addressed with improved restrictions.
Apple
CVE-2019-14899: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
vendor_apple·2020-07-15·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Product: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
CVE: CVE-2019-14899
Component: Kernel
Impact: An attacker in a privileged network position may be able to inject into active connections within a VPN tunnel
Description: A routing issue was addressed with improved restrictions.
Apple
CVE-2019-14899: iOS 13.6 and iPadOS 13.6
vendor_apple·2020-07-15·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2019-14899
Component: Kernel
Impact: An attacker in a privileged network position may be able to inject into active connections within a VPN tunnel
Description: A routing issue was addressed with improved restrictions.
Red Hat
VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel
vendor_redhat·2019-12-04·CVSS 7.4
CVE-2019-14899 [HIGH] CWE-300 VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel
VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.
A flaw was found in openvpn. A malicous access point or adjacent user can determine if a connected user is using a VPN by making positive inferences about the websites they are visiting,
GHSA
GHSA-rwr5-xr2c-7wc8: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to deter
ghsa_unreviewed·2022-05-24
CVE-2019-14899 [HIGH] CWE-300 GHSA-rwr5-xr2c-7wc8: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to deter
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.
OSV
CVE-2019-14899: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to deter
osv·2019-12-11·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to deter
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.
No detection rules found.
No public exploits indexed.
Bugzilla
openvpn: Blind in/on-path attacks against VPN-tunneled connections
bugzilla·2020-08-17·CVSS 7.4
CVE-2019-14899 [HIGH] openvpn: Blind in/on-path attacks against VPN-tunneled connections
openvpn: Blind in/on-path attacks against VPN-tunneled connections
As per the reporter:
This is reporting a vulnerability that allows an in/on-path attacker between a VPN client and VPN server to infer and inject arbitrary data into VPN-tunneled connections. This vulnerability is related to CVE-2019-14899, but has a few key differences.
- The attacker does not need to be the gateway or network adjacent, as described in CVE-2019-14899.
- The packets are not being spoofed "outside" of the tunnel. In the previous attack, the packets were sent to the wireless/ethernet interface and were still being processed by the kernel despite coming from a non-VPN interface, in this attack we are not subverting the tunnel by sending packets to the incorrect interface, but sending packets to the VPN ser
Bugzilla
CVE-2019-9461 kernel: information disclosure via VPN routing
bugzilla·2020-03-31·CVSS 7.4
CVE-2019-9461 [HIGH] CVE-2019-9461 kernel: information disclosure via VPN routing
CVE-2019-9461 kernel: information disclosure via VPN routing
A vulnerability was found in VPN routing in Kernel where there is a possible information disclosure. This could lead to remote information disclosure by an adjacent network attacker with no additional execution privileges needed. User interaction is not needed for exploitation.
References:
https://source.android.com/security/bulletin/pixel/2019-09-01
Discussion:
More references:
http://www.openwall.com/lists/oss-security/2019/12/05/1
http://www.openwall.com/lists/oss-security/2019/12/05/2
http://www.openwall.com/lists/oss-security/2019/12/08/1
---
(In reply to msiddiqu from comment #1)
> More references:
>
> http://www.openwall.com/lists/oss-security/2019/12/05/1
> http://www.openwall.com/lists/oss-security/2019/12/05/2
>
Bugzilla
CVE-2019-14899 openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-all]
bugzilla·2019-12-06·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899 openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-all]
CVE-2019-14899 openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fe
Bugzilla
CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-6]
bugzilla·2019-12-06·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-6]
CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2019-14899 openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [fedora-all]
bugzilla·2019-12-06·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899 openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [fedora-all]
CVE-2019-14899 openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [fedora-all]
bugzilla·2019-12-06·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [fedora-all]
CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
Bugzilla
CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-8]
bugzilla·2019-12-06·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-8]
CVE-2019-14899 ike: openvpn: ike: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel [epel-8]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-8.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2019-14899 VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel
bugzilla·2019-11-21·CVSS 7.4
CVE-2019-14899 [HIGH] CVE-2019-14899 VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel
CVE-2019-14899 VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel
A malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.
Discussion:
Public via:
https://seclists.org/oss-sec/2019/q4/122
https://www.openwall.com/lists/oss-security/2019/12/05/3
https://www.zdnet.com/article/new-vulnerability-lets-attackers-sniff-or-hijack-vpn-connections/
https://www.bleepingcomputer.com/news/security/
Checkpoint
9th December – Threat Intelligence Bulletin
blogs_checkpoint·2019-12-09
CVE-2019-14899 9th December – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th December – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 2nd December 2019, please download our Threat Intelligence bulletin .
TOP ATTACKS AND BREACHES
The Vietnam-linked APT group Ocean Lotus has breached networks of the car manufacturers BMW and Hyundai. The group, previously linked to different car vendor attacks, reportedly performed a watering hole attack and deployed the hacking tool Cobalt Strike to access the network of both companies.
Check Point IPS and
arXiv
Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities
arxiv_fulltext·2021-12-21
Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities
Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities
Mubin Ul Haque2 and
M. Ali Babar 3
Centre for Research on Engineering Software Technologies (CREST)
School of Computer Science, and Engineering, The University of Adelaide, Adelaide, Australia
Cyber Security Cooperative Research Centre, Australia
[email protected], [email protected]
plain
plain
## Abstract
Container technology, (e.g., Docker) is being widely adopted for deploying software infrastructures or applications in the form of container images.
Security vulnerabilities in the container images are a primary concern for developing containerized software.
Exploitation of the vulnerabilities could result in disastrous impact, such as loss of confidentiality, in
http://seclists.org/fulldisclosure/2020/Dec/32http://seclists.org/fulldisclosure/2020/Jul/23http://seclists.org/fulldisclosure/2020/Jul/24http://seclists.org/fulldisclosure/2020/Jul/25http://seclists.org/fulldisclosure/2020/Nov/20http://www.openwall.com/lists/oss-security/2020/08/13/2http://www.openwall.com/lists/oss-security/2020/10/07/3http://www.openwall.com/lists/oss-security/2021/07/05/1https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14899https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/https://support.apple.com/kb/HT211288https://support.apple.com/kb/HT211289https://support.apple.com/kb/HT211290https://support.apple.com/kb/HT211850https://support.apple.com/kb/HT211931http://seclists.org/fulldisclosure/2020/Dec/32http://seclists.org/fulldisclosure/2020/Jul/23http://seclists.org/fulldisclosure/2020/Jul/24http://seclists.org/fulldisclosure/2020/Jul/25http://seclists.org/fulldisclosure/2020/Nov/20http://www.openwall.com/lists/oss-security/2020/08/13/2http://www.openwall.com/lists/oss-security/2020/10/07/3http://www.openwall.com/lists/oss-security/2021/07/05/1https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14899https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/https://support.apple.com/kb/HT211288https://support.apple.com/kb/HT211289https://support.apple.com/kb/HT211290https://support.apple.com/kb/HT211850https://support.apple.com/kb/HT211931
2019-12-11
Published