cbcvebase.
CVE-2020-11810
published 2020-04-27

CVE-2020-11810: An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such…

PriorityP416low3.7CVSS 3.1
AVNACHPRNUINSUCNINAL
EPSS
1.61%
73.4th percentile
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianopenvpn< openvpn 2.4.9-1 (bookworm)openvpn 2.4.9-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
openvpnopenvpn>= 0 < 2.4.9-12.4.9-1
openvpnopenvpn>= 0 < 2.4.9-12.4.9-1
openvpnopenvpn>= 0 < 2.4.9-12.4.9-1
openvpnopenvpn>= 0 < 2.4.9-12.4.9-1
openvpnopenvpn>= 0 < 2.4.4-2ubuntu1.52.4.4-2ubuntu1.5
openvpnopenvpn>= 0 < 2.4.7-1ubuntu2.20.04.22.4.7-1ubuntu2.20.04.2
openvpnopenvpn>= 2.4.0 < 2.4.92.4.9

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.