Rewterz
Rewterz Threat Advisory – Multiple Palo Alto Security Vulnerabilities
September 10, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-38540 – Apache Airflow Security Vulnerability
September 10, 2021

Rewterz Threat Advisory – CVE-2021-3773 – OpenVPN for Linux and FreeBSD Security Vulnerability

Severity

High

Analysis Summary

CVE-2021-3773

OpenVPN for Linux and FreeBSD is vulnerable to a denial of service, caused by the lack of port sanity checking in natd and Netfilter. By sending specially-crafted packets, a remote attacker could exploit this vulnerability to cause a denial of service condition, deanonymization of clients, and redirection of connection to an attacker-controlled server.

Impact

  • Denial of Service
  • Information Disclosure

Affected Vendors

OpenVPN

Affected Products

  • OpenVPN OpenVPN 2.4.4

Remediation

Upgrade to the latest version of OpenVPN, available from the OpenVPN Web site. See References