Blame
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 1 | # Introduction |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 3 | In late November 2014 Dragana Damjanovic notified OpenVPN developers of a critical *denial of service* security vulnerability (CVE-2014-8104). The vulnerability allows a *tls-authenticated client* to crash the server by sending a too-short control channel packet to the server. In other words this vulnerability is denial of service only. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 5 | A fixed version of OpenVPN (2.3.6) was released 1st Dec 2014 at around 18:00 UTC. The fix was also backported to the OpenVPN 2.2 branch and released in OpenVPN 2.2.3, a source-only release. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 6 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 7 | ## Scope of the vulnerability |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 8 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 9 | This vulnerability affects all OpenVPN 2.x versions released since 2005. It is also possible that even older versions are affected. However, only *server availability* is affected. Confidentiality and authenticity of traffic are *not* affected. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 10 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 11 | The OpenVPN 3.x codebase used in most OpenVPN Connect clients (Android, iOS) is not vulnerable and not used on the server-side. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 12 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 13 | ## Mitigating factors |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 14 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 15 | Only *tls-authenticated* clients can trigger the vulnerability in the OpenVPN server. Thus both client certificates and TLS auth will protect against this exploit as long as all OpenVPN clients can be trusted to not be compromised and/or malicious. Note that username/password authentication does *not* protect against this exploit, and servers using `--client-cert-not-required` by definition have no client certificates to protect against this exploit. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 16 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 17 | In particular VPN service providers are affected, because anyone can get their hands on the necessary client certificates and TLS auth keys. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 18 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 19 | ## Has OpenVPN been successfully exploited? |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 20 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 21 | An OpenVPN server can be easily exploited (crashed) using this vulnerability by an authenticated client. However, we are not aware of this exploit being used in the wild before we released a fixed version (2.3.6). |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 22 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 23 | ## How do I fix this? |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 24 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 25 | Simply install a patched version of OpenVPN. If you're using official releases then, go for OpenVPN 2.3.6 or latest Git "master". If you're using OpenVPN from your operating system's software repositories then install an updated version from them. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 26 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 27 | If you're maintaining packages based on OpenVPN 2.2 you can get a backported patch from the Git repository's release/2.2 branch. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 28 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 29 | ## Is Access Server affected? |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 30 | |
| c4400a | Samuli Seppänen | 2025-02-27 10:25:40 | 31 | Access Server versions prior to 2.0.11 are vulnerable. The first fixed, non-vulnerable version is 2.0.11 - you should upgrade to it as soon as possible, especially if you suspect some clients might be malicious. |
