// For flags

CVE-2013-2061

Mandriva Linux Security Advisory 2013-167

Severity Score

5.9
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

La función openvpn_decrypt en el archivo crypto.c en OpenVPN versiones 2.3.0 y anteriores, cuando se ejecuta en modo UDP, permite a los atacantes remotos obtener información confidencial por medio de un ataque de sincronización que implica una función de comparación HMAC que no se ejecuta en tiempo constante y un ataque de tipo padding oracle en el cifrado en modo CBC.

OpenVPN 2.3.0 and earlier running in UDP mode are subject to chosen ciphertext injection due to a non-constant-time HMAC comparison function. Plaintext recovery may be possible using a padding oracle attack on the CBC mode cipher implementation of the crypto library, optimistically at a rate of about one character per 3 hours. PolarSSL seems vulnerable to such an attack; the vulnerability of OpenSSL has not been verified or tested.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-02-19 CVE Reserved
  • 2013-05-28 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
<= 2.3.0
Search vendor "Openvpn" for product "Openvpn" and version " <= 2.3.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.2.0
Search vendor "Openvpn" for product "Openvpn" and version "1.2.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.2.1
Search vendor "Openvpn" for product "Openvpn" and version "1.2.1"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.3.0
Search vendor "Openvpn" for product "Openvpn" and version "1.3.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.3.1
Search vendor "Openvpn" for product "Openvpn" and version "1.3.1"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.3.2
Search vendor "Openvpn" for product "Openvpn" and version "1.3.2"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.4.0
Search vendor "Openvpn" for product "Openvpn" and version "1.4.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.4.1
Search vendor "Openvpn" for product "Openvpn" and version "1.4.1"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.4.2
Search vendor "Openvpn" for product "Openvpn" and version "1.4.2"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.4.3
Search vendor "Openvpn" for product "Openvpn" and version "1.4.3"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.5.0
Search vendor "Openvpn" for product "Openvpn" and version "1.5.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
1.6.0
Search vendor "Openvpn" for product "Openvpn" and version "1.6.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
2.1.0
Search vendor "Openvpn" for product "Openvpn" and version "2.1.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn
Search vendor "Openvpn" for product "Openvpn"
2.2.0
Search vendor "Openvpn" for product "Openvpn" and version "2.2.0"
-
Affected
Openvpn
Search vendor "Openvpn"
Openvpn Access Server
Search vendor "Openvpn" for product "Openvpn Access Server"
2.0.0
Search vendor "Openvpn" for product "Openvpn Access Server" and version "2.0.0"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
11.4
Search vendor "Opensuse" for product "Opensuse" and version "11.4"
-
Affected