The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openvpn | Aug 30, 2017 | Nov 17, 2013 |
| Debian | — | Upgrade openvpn | Jul 30, 2024 | Nov 18, 2013 |
| Freebsd | — | Upgrade openvpn | Dec 10, 2025 | Mar 31, 2013 |
| Gentoo Linux | — | Upgrade net-misc/openvpn. | Oct 30, 2017 | Nov 17, 2013 |
| Suse | — | Upgrade openvpn-auth-pam-pluginUpgrade openvpnUpgrade openvpn-down-root-plugin | Dec 12, 2013 | Nov 17, 2013 |
| Ubuntu | — | Upgrade openvpn | Nov 8, 2024 | Nov 18, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub