CVE-2020-11810
published 2020-04-27CVE-2020-11810: An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such…
PriorityP416low3.7CVSS 3.1
AVNACHPRNUINSUCNINAL
EPSS
1.61%
73.4th percentile
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openvpn | < openvpn 2.4.9-1 (bookworm) | openvpn 2.4.9-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openvpn | openvpn | >= 0 < 2.4.9-1 | 2.4.9-1 |
| openvpn | openvpn | >= 0 < 2.4.9-1 | 2.4.9-1 |
| openvpn | openvpn | >= 0 < 2.4.9-1 | 2.4.9-1 |
| openvpn | openvpn | >= 0 < 2.4.9-1 | 2.4.9-1 |
| openvpn | openvpn | >= 0 < 2.4.4-2ubuntu1.5 | 2.4.4-2ubuntu1.5 |
| openvpn | openvpn | >= 0 < 2.4.7-1ubuntu2.20.04.2 | 2.4.7-1ubuntu2.20.04.2 |
| openvpn | openvpn | >= 2.4.0 < 2.4.9 | 2.4.9 |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6crj-vqv7-qq9r: An issue was discovered in OpenVPN 2
ghsa_unreviewed·2022-05-24
CVE-2020-11810 [MEDIUM] CWE-362 GHSA-6crj-vqv7-qq9r: An issue was discovered in OpenVPN 2
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.
OSV
openvpn vulnerabilities
osv·2021-05-04·CVSS 3.7
CVE-2020-11810 [LOW] openvpn vulnerabilities
openvpn vulnerabilities
It was discovered that OpenVPN incorrectly handled certain data channel v2
packets. A remote attacker could possibly use this issue to inject packets
using a victim's peer-id. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11810)
It was discovered that OpenVPN incorrectly handled deferred authentication.
When a server is configured to use deferred authentication, a remote
attacker could possibly use this issue to bypass authentication and access
control channel data. (CVE-2020-15078)
OSV
CVE-2020-11810: An issue was discovered in OpenVPN 2
osv·2020-04-27·CVSS 3.7
CVE-2020-11810 [LOW] CVE-2020-11810: An issue was discovered in OpenVPN 2
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.
Ubuntu
OpenVPN vulnerabilities
vendor_ubuntu·2021-05-04·CVSS 3.7
CVE-2020-15078 [LOW] OpenVPN vulnerabilities
Title: OpenVPN vulnerabilities
Summary: Several security issues were fixed in OpenVPN.
It was discovered that OpenVPN incorrectly handled certain data channel v2
packets. A remote attacker could possibly use this issue to inject packets
using a victim's peer-id. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11810)
It was discovered that OpenVPN incorrectly handled deferred authentication.
When a server is configured to use deferred authentication, a remote
attacker could possibly use this issue to bypass authentication and access
control channel data. (CVE-2020-15078)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-11810: openvpn - An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a ...
vendor_debian·2020·CVSS 3.7
CVE-2020-11810 [LOW] CVE-2020-11810: openvpn - An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a ...
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
forky: resolved (fixed in 2.4.9-1)
sid: resolved (fixed in 2.4.9-1)
trixie: resolved (fixed in 2.4.9-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1169925https://community.openvpn.net/openvpn/ticket/1272https://github.com/OpenVPN/openvpn/commit/37bc691e7d26ea4eb61a8a434ebd7a9ae76225abhttps://lists.debian.org/debian-lts-announce/2022/05/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FGHHV4YZANZW45KZTJJGVGPFMSXYRCKZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JII7RYYYRBPQNEGGVSOXCM7JUZ43T3VH/https://patchwork.openvpn.net/patch/1079/https://security-tracker.debian.org/tracker/CVE-2020-11810https://bugzilla.suse.com/show_bug.cgi?id=1169925https://community.openvpn.net/openvpn/ticket/1272https://github.com/OpenVPN/openvpn/commit/37bc691e7d26ea4eb61a8a434ebd7a9ae76225abhttps://lists.debian.org/debian-lts-announce/2022/05/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FGHHV4YZANZW45KZTJJGVGPFMSXYRCKZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JII7RYYYRBPQNEGGVSOXCM7JUZ43T3VH/https://patchwork.openvpn.net/patch/1079/https://security-tracker.debian.org/tracker/CVE-2020-11810
2020-04-27
Published