Reachable assertion in OpenVPN Server - CVE-2025-2704

 

Reachable assertion in OpenVPN Server - CVE-2025-2704

Published: April 3, 2025


Vulnerability identifier: #VU106925
CSH Severity: Medium
CVSS v4 BT: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-2704
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion in server mode using TLS-crypt-v2. A remote attacker can perform a denial of service attack against the VPN server by replaying network packets in the early handshake phase.

Successful exploitation of the vulnerability requires a valid tls-crypt-v2 client key or network observation of a handshake with a valid tls-crypt-v2 client key.


Affected software

OpenVPN Server
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
openvpn-debuginfo
openvpn-dco-devel
openvpn-dco
openvpn-auth-pam-plugin-debuginfo
openvpn-dco-debuginfo
openvpn-dco-debugsource
openvpn-down-root-plugin
openvpn
openvpn-debugsource
openvpn-auth-pam-plugin
openvpn-devel
openvpn-down-root-plugin-debuginfo
openvpn-help
openvpn (Ubuntu package)

How to mitigate CVE-2025-2704

Install updates from vendor's website.

OpenVPN Server - update to 2.6.14
openvpn-debuginfo - update to 2.6.8-150600.3.17.1
openvpn-dco-devel - update to 2.6.8-150600.3.17.1
openvpn-dco - update to 2.6.8-150600.3.17.1
openvpn-auth-pam-plugin-debuginfo - update to 2.6.8-150600.3.17.1
openvpn-dco-debuginfo - update to 2.6.8-150600.3.17.1
openvpn-dco-debugsource - update to 2.6.8-150600.3.17.1
openvpn-down-root-plugin - update to 2.6.8-150600.3.17.1
openvpn - update to 2.6.8-150600.3.17.1
openvpn-debugsource - update to 2.6.8-150600.3.17.1
openvpn-auth-pam-plugin - update to 2.6.8-150600.3.17.1
openvpn-devel - update to 2.6.8-150600.3.17.1
openvpn-down-root-plugin-debuginfo - update to 2.6.8-150600.3.17.1
openvpn-help - update to 2.6.9-4
openvpn - update to 2.6.9-4
openvpn-debuginfo - update to 2.6.9-4
openvpn-debugsource - update to 2.6.9-4
openvpn-devel - update to 2.6.9-4
openvpn (Ubuntu package) - addressed in versions 2.6.12-0ubuntu0.24.04.3, 2.6.12-1ubuntu1.2
openvpn - addressed in versions 2.6.14-1.fc40, 2.6.14-1.fc41, 2.6.14-1.fc42

External References

Related Security Bulletins