OpenVPN versions 2.3.0 and earlier, when operating in UDP mode, are susceptible to chosen ciphertext injection due to a comparison function for HMAC that does not execute in constant time. This vulnerability could potentially allow plaintext recovery through a padding oracle attack on the CBC mode cipher used in the cryptographic library. Notably, PolarSSL is affected by this issue; however, the susceptibility of OpenSSL has not been confirmed or tested.
+
OpenVPN 2.3.0 and earlier running in UDP mode are subject to chosen ciphertext injection due to a non-constant-time HMAC comparison function. Plaintext recovery may be possible using a padding oracle attack on the CBC mode cipher implementation of the crypto library, optimistically at a rate of about one character per 3 hours. PolarSSL seems vulnerable to such an attack; the vulnerability of OpenSSL has not been verified or tested.
-
# Severity
+
# Severity
-
Typically, OpenVPN servers are configured to silently discard packets that do not have the correct HMAC. Consequently, measuring the processing time for these packets is challenging without a man-in-the-middle (MITM) position. Practically, executing the attack might require specific information about the target.
+
OpenVPN servers are typically configured to silently drop packets with the wrong HMAC. For this reason measuring the processing time of the packets is not trivial without a MITM position. In practice, the attack likely needs some target-specific information to be effective.
-
The impact of this vulnerability is considered low. The risk heightens significantly if OpenVPN is set up to use a null-cipher, as this configuration could allow arbitrary plaintext injections, thus fully exposing the vulnerability.
+
The severity of this vulnerability can be considered low. Only if OpenVPN is configured to use a null-cipher, arbitrary
+
plain-text can be injected which can completely open up this attack vector.
-
# Affected Versions
+
# Affected versions
-
Versions of OpenVPN up to 2.3.0 are affected. A correction for this issue is implemented in OpenVPN 2.3.1 and later versions, as detailed in the [commit f375aa67cc](https://github.com/OpenVPN/openvpn/commit/11d21349a4e7e38a025849479b36ace7c2eec2ee). This vulnerability has been cataloged as CVE-2013-2061.
\
No newline at end of file
+
OpenVPN 2.3.0 and earlier are vulnerable. A fix ([commit f375aa67cc](https://github.com/OpenVPN/openvpn/commit/11d21349a4e7e38a025849479b36ace7c2eec2ee)) is included in OpenVPN 2.3.1 and later. This issue has been assigned to CVE-2013-2061.