Junglewise Threat Intelligence

CVE-2014-9754: Viprinet Multichannel VPN Router 300 certificate validation failure

CVE-2014-9754 · Severity: medium · CVSS 5.9 · Published 2017-01-20

Executive brief

A vulnerability in the Viprinet Multichannel VPN Router 300 allows an attacker to intercept and potentially modify encrypted traffic. The device's VPN client fails to verify the identity of the server it connects to, meaning it could unknowingly connect to a malicious third party. This could lead to a 'man-in-the-middle' attack where sensitive corporate data transmitted over the VPN is compromised.

Technical details

The hardware VPN client in Viprinet Multichannel VPN Router 300 (firmware versions 2013070830 and 2013080900) fails to perform identity verification of remote VPN endpoints. Specifically, the client does not validate the endpoint's SSL/TLS certificate or key during the initial handshake before proceeding with the protocol exchange. An attacker positioned between the client and the server can intercept the connection and impersonate the legitimate VPN gateway. This vulnerability allows for Man-in-the-Middle (MitM) attacks against the VPN tunnel. The issue was addressed in firmware versions 2014013131 and 2014020702.

Affected products

  • Viprinet Multichannel VPN Router 300 firmware 2013070830, 2013080900

Timeline

  • 2016-02-03: disclosed: Public disclosure via Full Disclosure mailing list
  • 2017-01-20: advisory: NVD publication date

References

Related threats