CVE-2019-14899
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.
Published
2019-12-11T15:15:14.263
Last Modified
2024-11-21T04:27:38.590
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 7.4 (HIGH)
CVSSv2 Vector
AV:A/AC:M/Au:S/C:P/I:P/A:P
- Access Vector: ADJACENT_NETWORK
- Access Complexity: MEDIUM
- Authentication: SINGLE
- Confidentiality Impact: PARTIAL
- Integrity Impact: PARTIAL
- Availability Impact: PARTIAL
Exploitability Score
4.4
Impact Score
6.4
Weaknesses
-
Type: Primary
CWE-300
-
Type: Secondary
NVD-CWE-Other
Affected Vendors & Products
References
-
http://seclists.org/fulldisclosure/2020/Dec/32
Mailing List, Third Party Advisory
([email protected])
-
http://seclists.org/fulldisclosure/2020/Jul/23
Mailing List, Third Party Advisory
([email protected])
-
http://seclists.org/fulldisclosure/2020/Jul/24
Mailing List, Third Party Advisory
([email protected])
-
http://seclists.org/fulldisclosure/2020/Jul/25
Mailing List, Third Party Advisory
([email protected])
-
http://seclists.org/fulldisclosure/2020/Nov/20
Mailing List, Third Party Advisory
([email protected])
-
http://www.openwall.com/lists/oss-security/2020/08/13/2
Mailing List, Third Party Advisory
([email protected])
-
http://www.openwall.com/lists/oss-security/2020/10/07/3
Mailing List, Third Party Advisory
([email protected])
-
http://www.openwall.com/lists/oss-security/2021/07/05/1
Mailing List, Third Party Advisory
([email protected])
-
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14899
Issue Tracking, Third Party Advisory
([email protected])
-
https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/
Third Party Advisory
([email protected])
-
https://support.apple.com/kb/HT211288
Third Party Advisory
([email protected])
-
https://support.apple.com/kb/HT211289
Third Party Advisory
([email protected])
-
https://support.apple.com/kb/HT211290
Third Party Advisory
([email protected])
-
https://support.apple.com/kb/HT211850
Third Party Advisory
([email protected])
-
https://support.apple.com/kb/HT211931
Third Party Advisory
([email protected])
-
http://seclists.org/fulldisclosure/2020/Dec/32
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://seclists.org/fulldisclosure/2020/Jul/23
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://seclists.org/fulldisclosure/2020/Jul/24
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://seclists.org/fulldisclosure/2020/Jul/25
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://seclists.org/fulldisclosure/2020/Nov/20
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.openwall.com/lists/oss-security/2020/08/13/2
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.openwall.com/lists/oss-security/2020/10/07/3
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.openwall.com/lists/oss-security/2021/07/05/1
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14899
Issue Tracking, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/kb/HT211288
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/kb/HT211289
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/kb/HT211290
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/kb/HT211850
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/kb/HT211931
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)