Blame

c4f02d Samuli Seppänen 2025-01-29 08:37:37 1
# OpenSSL CCS Injection Vulnerability (CVE-2014-0224)
23cfd2 Samuli Seppänen 2025-02-27 09:58:09 2
On June 5th, 2014, a number of vulnerabilities in OpenSSL were disclosed (see https://www.openssl.org/news/secadv_20140605.txt). One of those, the CCS Injection Vulnerability, affects OpenVPN. This page discusses the consequences for OpenVPN users.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 3
4
## What does the CCS Injection Vulnerability mean?
82dd71 novaflash 2025-07-02 16:22:27 5
In short: if both the client and the server are running a vulnerable version of OpenSSL, an active attacker with a man-in-the-middle position can trick OpenSSL to use keys known to the attacker. This means the attacker can read and even manipulate everything on the TLS connection. In the OpenVPN case, that includes the traffic protection keys for your VPN data, and thus your VPN data. For more information, visit the CCS Injection Vulnerability page at http://ccsinjection.lepidum.co.jp/ or check the CVE at [Mitre](https://www.cve.org/CVERecord?id=CVE-2014-0224).
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
23cfd2 Samuli Seppänen 2025-02-27 09:58:09 7
Use of [TLS auth](/PageS/Hardening) prevents this vulnerability from being exploited.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 8
9
## What should I do?
23cfd2 Samuli Seppänen 2025-02-27 09:58:09 10
* Update your OpenSSL and restart OpenVPN (and any other daemons using it).
82dd71 novaflash 2025-07-02 16:22:27 11
* If you're using the OpenVPN Windows installer upgrade to the [latest OpenVPN release](https://openvpn.net/index.php/download/community-downloads.html).
23cfd2 Samuli Seppänen 2025-02-27 09:58:09 12
* Use TLS-auth as an extra layer of protection (see [Hardening](/Pages/Hardening)).
c4f02d Samuli Seppänen 2025-01-29 08:37:37 13
14
## Do I need to create new private keys and certificates?
15
No, those are not leaked by this vulnerability. The keys an attacker could intercept are the temporary TLS and VPN data channel keys, which are freshly generated for each new connection.
16
17
## Do the six other OpenSSL vulnerabilities affect OpenVPN?
23cfd2 Samuli Seppänen 2025-02-27 09:58:09 18
No. Current OpenVPN releases (that is, upto 2.3.4) do not use DTLS, SSL_MODE_RELEASE_BUFFERS or ECDH, and are thus not affected by bugs in those components.