An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openvpn | Aug 22, 2024 | Apr 27, 2020 |
| Amazon_linux | — | Upgrade openvpn | Jul 30, 2020 | Apr 13, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 27, 2020 |
| Debian | — | Upgrade openvpn | May 5, 2022 | Apr 27, 2020 |
| Freebsd | — | Upgrade openvpn-develUpgrade openvpnUpgrade openvpn-mbedtls | Apr 17, 2020 | Apr 16, 2020 |
| Suse | — | Upgrade openvpnUpgrade openvpn-develUpgrade openvpn-auth-pam-pluginUpgrade openvpn-down-root-plugin | May 18, 2021 | Apr 13, 2020 |
| Ubuntu | — | Upgrade openvpn | May 5, 2021 | Apr 13, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub