Vulnerabilities in VPNs: Paper presented at the Privacy Enhancing Technologies Symposium 2024
ID: 86c17065-616a-502c-96f6-8545cee69d56
STIX ID: report--86c17065-616a-502c-96f6-8545cee69d56
Feed Name: The Citizen Lab
This report presents the "port shadow" vulnerability affecting VPN servers using OS connection-tracking frameworks (notably OpenVPN and WireGuard on Linux/Netfilter and some FreeBSD configurations). The flaw allows a malicious VPN client (or remote actor manipulating packets) to shadow a victim's port state, enabling deanonymization, DNS injection, connection hijacking, port scanning, and denial-of-service against other VPN clients sharing the same server; the authors disclose mitigations (firewall rules, source-port restrictions, limiting concurrent connections), attest to having followed coordinated disclosure, and reference CVE-2021-3773 (CVSSv3 9.8).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
