Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Security alert on OpenVPN 2.6.5 (PfSense+ 23.09) CVE-2023-46850

    Scheduled Pinned Locked Moved OpenVPN
    13 Posts 5 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @mc.gyver.reboot
      last edited by

      @mc-gyver-reboot

      https://redmine.pfsense.org/issues/14985#change-70888

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      L M 2 Replies Last reply Reply Quote 1
      • L
        Luca De Andreis @michmoor
        last edited by

        @michmoor

        OK, well for CE release that is coming soon, but for plus that just came out 23.09 will need to wait for 24.03 (as specified in the page mentioned link) ?

        jimpJ 2 Replies Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate @Luca De Andreis
          last edited by

          @Luca-De-Andreis said in Security alert on OpenVPN 2.6.5 (PfSense+ 23.09) CVE-2023-46850:

          @michmoor

          OK, well for CE release that is coming soon, but for plus that just came out 23.09 will need to wait for 24.03 (as specified in the page mentioned link) ?

          We may pick back the change so users on 23.09 can upgrade it manually in the shell if they want to do so. We're still weighing our options there.

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 2
          • M
            mc.gyver.reboot @michmoor
            last edited by

            @michmoor

            Thanks you very much for the reply !
            So I will wait for version 2.7.1 of pfsense CE.

            I would like to come back to one point, namely whether version 2.6.x of pfsense CE is affected by these vulnerabilities.
            Would you have the information?

            THANKS

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate @Luca De Andreis
              last edited by

              @Luca-De-Andreis said in Security alert on OpenVPN 2.6.5 (PfSense+ 23.09) CVE-2023-46850:

              @michmoor

              OK, well for CE release that is coming soon, but for plus that just came out 23.09 will need to wait for 24.03 (as specified in the page mentioned link) ?

              We pulled the updated version back into 23.09. You can update it manually from the shell (e.g. pkg-static upgrade openvpn) but there also happens to be an update for the OpenVPN client export package. If you update that in the GUI, it also pulls in the OpenVPN upgrade:

              Installed packages to be UPGRADED:
              	openvpn: 2.6.5 -> 2.6.7_1 [pfSense]
              	openvpn-client-export: 2.6.5 -> 2.6.7 [pfSense]
              	pfSense-pkg-openvpn-client-export: 1.9_1 -> 1.9.2 [pfSense]
              

              You'll want to restart the daemons manually after that (or reboot) to ensure they are running the updated version.

              @mc-gyver-reboot said in Security alert on OpenVPN 2.6.5 (PfSense+ 23.09) CVE-2023-46850:

              @michmoor
              So I will wait for version 2.7.1 of pfsense CE.

              That is out now, it was released yesterday evening.

              I would like to come back to one point, namely whether version 2.6.x of pfsense CE is affected by these vulnerabilities.

              Most likely, it is running an older version of OpenVPN. That version is no longer maintained, anyone on CE should upgrade to 2.7.1.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              M M 2 Replies Last reply Reply Quote 3
              • M
                mcury @jimp
                last edited by

                @jimp Hello Jimp, thanks for that, really appreciate how fast you guys worked to solve that issue.

                But, do you know if that package is already available, for me it seems that isn't.

                [23.09-RELEASE][root@pfsense.home.arpa]/root: pkg-static upgrade openvpn
                Updating pfSense-core repository catalogue...
                Fetching meta.conf:   0%
                pfSense-core repository is up to date.
                Updating pfSense repository catalogue...
                Fetching meta.conf:   0%
                pfSense repository is up to date.
                All repositories are up to date.
                Checking integrity... done (0 conflicting)
                Your packages are up to date.
                

                dead on arrival, nowhere to be found.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by jimp

                  Did you already update the export package in the GUI?

                  What happens if you run pkg-static info -x openvpn?

                  EDIT: Nevermind it looks like some users may not be seeing the updates yet, should be resolved shortly.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  M 1 Reply Last reply Reply Quote 1
                  • M
                    mcury @jimp
                    last edited by

                    @jimp said in Security alert on OpenVPN 2.6.5 (PfSense+ 23.09) CVE-2023-46850:

                    EDIT: Nevermind it looks like some users may not be seeing the updates yet, should be resolved shortly.

                    Oh, that's ok then, I'll be trying again later, thanks a lot ๐Ÿ‘

                    dead on arrival, nowhere to be found.

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      Should be available for everyone now, give it another try

                      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mcury @jimp
                        last edited by

                        @jimp said in Security alert on OpenVPN 2.6.5 (PfSense+ 23.09) CVE-2023-46850:

                        Should be available for everyone now, give it another try

                        Upgraded successfully.

                        Installed packages to be UPGRADED:
                        	pkg: 1.20.8_1 -> 1.20.8_2 [pfSense]
                        
                        Installed packages to be UPGRADED:
                        	openvpn: 2.6.5 -> 2.6.7_1 [pfSense]
                        

                        dead on arrival, nowhere to be found.

                        1 Reply Last reply Reply Quote 0
                        • M
                          mc.gyver.reboot @jimp
                          last edited by

                          @jimp
                          Hi,

                          thanks for the answers !

                          Regarding the fact that the pfsense 2.6.0 CE version is impacted, for my part I was able to confirm that last week that on one of my firewalls in 2.6.0 not up to date I had available the 2.5.4 package of openvpn while today I have version 2.6.4.
                          What is strange is that as https://cve.mitre.org/ indicates, only versions 2.6.0 to 2.6.6 are impacted...

                          09adf418-f563-483c-a369-5e4d60d0cff7-image.png

                          0ee2dbd6-cc83-41b3-9214-51f9a43b7792-image.png

                          911df671-4911-41c9-8a99-96362055474f-image.png

                          49e14baa-a9bd-40b3-997f-36603c82f552-image.png

                          To conclude, you must upgrade to pfsense CE version 2.7.1

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.