CVE-2013-2061
Published Nov 18, 2013
Last updated 5 years ago
Overview
- Description
- The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.6
- Impact score
- 2.9
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC35891F-BC4F-4DBB-8879-4952685D419E", "versionEndIncluding": "2.3.0" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "912E57A3-A4D0-4736-858F-51A500E886B8" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13960B6E-F1E8-49E5-88A0-ECCC938AC4DC" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "862743EA-7B6E-4478-AD90-1F930E97BB2E" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79114721-FA19-43FF-8030-74652FCF937B" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A3AF5D2-21CC-4243-A2A4-99273B7AD9D5" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B693F0CA-7A3A-42CA-A6BE-62D840CE336C" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "345C3123-7E73-4094-8764-8BF881B6ABE7" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F00F2FF1-9CC2-446B-9468-1FB7D40371E7" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB625AC3-B428-44BB-99F4-F0FE00DA1C5D" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C25DDCBB-798B-43BF-88FF-2EDB57BEA01F" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:1.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3F6FE9B-62E0-47E3-A977-DA51249A353B" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88C2922E-6E95-45BF-ABF1-B1D799769DB5" }, { "criteria": "cpe:2.3:a:openvpn:openvpn:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D915A07-3B93-4D7C-8D52-73B696392B46" }, { "criteria": "cpe:2.3:a:openvpn:openvpn_access_server:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "486CD3E2-1B1A-4A1D-98ED-0E2EEAB0A0CF" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE554781-1EB9-446E-911F-6C11970C47F4" } ], "operator": "OR" } ] } ]