Access control error in OpenVPN for Windows - CVE-2016-6329

 

Access control error in OpenVPN for Windows - CVE-2016-6329

Published: September 8, 2016 / Updated: September 29, 2017


Vulnerability identifier: #VU380
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6329
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows attackers to gain access to potentially sensitive information.

The vulnerability exists due to capturing of long duration Blowfish CBC mode encrypted TLS session. Repeated sending of communication protocol with parts of the plaintext helps attackers to reconstruct the secret information.

Successful exploitation of this vulnerability may allow a remote attacker to access potentially sensitive data.


Affected software

OpenVPN for Windows
Fedora
IBM i
SUSE Linux
Ubuntu
IBM Cloud Pak for Data Scheduling
Dell DataIQ
openvpn

How to mitigate CVE-2016-6329

The vendor plans to issue a new version 2.3.12.

IBM Cloud Pak for Data Scheduling - update to 5.2.0
Dell DataIQ - update to 2.2.2.0
openvpn - addressed in versions 2.3.12-1.el5, 2.3.12-1.el6, 2.3.12-1.el7, 2.3.12-1.fc23, 2.3.12-1.fc24, 2.3.12-1.fc25

External References

Related Security Bulletins