CVE-2021-3773: Infoleak
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
Other sources
OpenVPN's use of Netfilter makes it susceptible to several attacks that can cause denial-of-service, deanonymization of clients, or redirection of a victim client connection to an attacker controlled server.
Reference: https://www.openwall.com/lists/oss-security/2021/09/08/3 https://breakpointingbad.com/2021/09/08/Port-Shadows-via-Network-Alchemy.html
— Red Hat
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3773?
CVE-2021-3773 is a vulnerability in netfilter that allows an attacker to infer openvpn connection endpoint information.
How severe is CVE-2021-3773?
CVE-2021-3773 has a severity rating of 9.8, which is classified as critical.
Which software versions are affected by CVE-2021-3773?
The affected software versions include kernel 5.15.15, kernel-rt 4.18.0-372.9.1.rt7.166.el8, kernel 4.18.0-372.9.1.el8, Linux kernel up to version 5.14, Fedora 34, Redhat Enterprise Linux 6.0, 7.0, and 8.0, Oracle Communications Cloud Native Core Binding Support Function 22.1.3, Oracle Communications Cloud Native Core Network Exposure Function 22.1.1, and Oracle Communications Cloud Native Core Policy 22.2.0.
How can an attacker exploit CVE-2021-3773?
An attacker can exploit CVE-2021-3773 to infer openvpn connection endpoint information and use it for further network attacks.
Are there any references for CVE-2021-3773?
Yes, you can find references for CVE-2021-3773 at the following links: [link1](https://www.openwall.com/lists/oss-security/2021/09/08/3), [link2](https://breakpointingbad.com/2021/09/08/Port-Shadows-via-Network-Alchemy.html), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2006005).