Exploit Summary
OpenVPN versions 2.3.0 and earlier, when operating in UDP mode, are susceptible to chosen ciphertext injection due to a comparison function for HMAC that does not execute in constant time. This vulnerability could potentially allow plaintext recovery through a padding oracle attack on the CBC mode cipher used in the cryptographic library. Notably, PolarSSL is affected by this issue; however, the susceptibility of OpenSSL has not been confirmed or tested.
Severity
Typically, OpenVPN servers are configured to silently discard packets that do not have the correct HMAC. Consequently, measuring the processing time for these packets is challenging without a man-in-the-middle (MITM) position. Practically, executing the attack might require specific information about the target.
The impact of this vulnerability is considered low. The risk heightens significantly if OpenVPN is set up to use a null-cipher, as this configuration could allow arbitrary plaintext injections, thus fully exposing the vulnerability.
Affected Versions
Versions of OpenVPN up to 2.3.0 are affected. A correction for this issue is implemented in OpenVPN 2.3.1 and later versions, as detailed in the commit f375aa67cc. This vulnerability has been cataloged as CVE-2013-2061.
