Blame

c4400a Samuli Seppänen 2025-02-27 10:25:40 1
# Introduction 
c4f02d Samuli Seppänen 2025-01-29 08:37:37 2
c4400a Samuli Seppänen 2025-02-27 10:25:40 3
In late November 2014 Dragana Damjanovic notified OpenVPN developers of a critical *denial of service* security vulnerability (CVE-2014-8104). The vulnerability allows a *tls-authenticated client* to crash the server by sending a too-short control channel packet to the server. In other words this vulnerability is denial of service only.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
c4400a Samuli Seppänen 2025-02-27 10:25:40 5
A fixed version of OpenVPN (2.3.6) was released 1st Dec 2014 at around 18:00 UTC. The fix was also backported to the OpenVPN 2.2 branch and released in OpenVPN 2.2.3, a source-only release.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
c4400a Samuli Seppänen 2025-02-27 10:25:40 7
## Scope of the vulnerability
c4f02d Samuli Seppänen 2025-01-29 08:37:37 8
c4400a Samuli Seppänen 2025-02-27 10:25:40 9
This vulnerability affects all OpenVPN 2.x versions released since 2005. It is also possible that even older versions are affected. However, only *server availability* is affected. Confidentiality and authenticity of traffic are *not* affected.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 10
c4400a Samuli Seppänen 2025-02-27 10:25:40 11
The OpenVPN 3.x codebase used in most OpenVPN Connect clients (Android, iOS) is not vulnerable and not used on the server-side.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 12
c4400a Samuli Seppänen 2025-02-27 10:25:40 13
## Mitigating factors
c4f02d Samuli Seppänen 2025-01-29 08:37:37 14
c4400a Samuli Seppänen 2025-02-27 10:25:40 15
Only *tls-authenticated* clients can trigger the vulnerability in the OpenVPN server. Thus both client certificates and TLS auth will protect against this exploit as long as all OpenVPN clients can be trusted to not be compromised and/or malicious. Note that username/password authentication does *not* protect against this exploit, and servers using `--client-cert-not-required` by definition have no client certificates to protect against this exploit.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 16
c4400a Samuli Seppänen 2025-02-27 10:25:40 17
In particular VPN service providers are affected, because anyone can get their hands on the necessary client certificates and TLS auth keys.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 18
c4400a Samuli Seppänen 2025-02-27 10:25:40 19
## Has OpenVPN been successfully exploited?
c4f02d Samuli Seppänen 2025-01-29 08:37:37 20
c4400a Samuli Seppänen 2025-02-27 10:25:40 21
An OpenVPN server can be easily exploited (crashed) using this vulnerability by an authenticated client. However, we are not aware of this exploit being used in the wild before we released a fixed version (2.3.6).
c4f02d Samuli Seppänen 2025-01-29 08:37:37 22
c4400a Samuli Seppänen 2025-02-27 10:25:40 23
## How do I fix this?
c4f02d Samuli Seppänen 2025-01-29 08:37:37 24
c4400a Samuli Seppänen 2025-02-27 10:25:40 25
Simply install a patched version of OpenVPN. If you're using official releases then, go for OpenVPN 2.3.6 or latest Git "master". If you're using OpenVPN from your operating system's software repositories then install an updated version from them.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 26
c4400a Samuli Seppänen 2025-02-27 10:25:40 27
If you're maintaining packages based on OpenVPN 2.2 you can get a backported patch from the Git repository's release/2.2 branch.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 28
c4400a Samuli Seppänen 2025-02-27 10:25:40 29
## Is Access Server affected?
c4f02d Samuli Seppänen 2025-01-29 08:37:37 30
c4400a Samuli Seppänen 2025-02-27 10:25:40 31
Access Server versions prior to 2.0.11 are vulnerable. The first fixed, non-vulnerable version is 2.0.11 - you should upgrade to it as soon as possible, especially if you suspect some clients might be malicious.