{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"Inferring and Hijacking VPN-Tunneled TCP Connections","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2019-00002","status":"final","version":"18","initial_release_date":"2019-12-09T10:00:00+00:00","current_release_date":"2026-08-18T21:55:10.275562+00:00","revision_history":[{"date":"2019-12-09T10:00:00+00:00","number":"18","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2019-00002"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2019-14899"}],"notes":[{"category":"summary","text":"On December 8th, 2019, security researcher William Tolley published vulnerabilities found in multiple Linux and Unix operating systems, allowing the attacker some access to the VPN. An attacker using this technique could compromise SSL VPN, IPsec, and WireGuard (a VPN application) connections. The attacker must be local to the vulnerable system and view all incoming and outgoing traffic to the system. The attacker uses packet-size analyses to determine the VPN packets and attempts to take over a connection by spoofing SYN/ACK packets. When successful, an attacker could compromise the VPN and potentially interfere with protected traffic.\n\nThe Firebox uses an SSL VPN client for Management Tunnels and BOVPN-Over-TLS. It is not affected by this vulnerability.\n\nFor this attack to succeed, a specially crafted packet is sent to the victim. When the crafted packet contains the correct IP, the vulnerable system will respond with a reset. The Firebox does not respond to this packet no matter if the virtual IP address is correct or not.\n\nWhile the vulnerability does not affect WatchGuard devices, it could still compromise VPN connections to a Firebox if the client OS is vulnerable.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Fireware OS all versions","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"On December 8th, 2019, security researcher William Tolley published vulnerabilities found in multiple Linux and Unix operating systems, allowing the attacker some access to the VPN. An attacker using this technique could compromise SSL VPN, IPsec, and WireGuard (a VPN application) connections. The attacker must be local to the vulnerable system and view all incoming and outgoing traffic to the system. The attacker uses packet-size analyses to determine the VPN packets and attempts to take over a connection by spoofing SYN/ACK packets. When successful, an attacker could compromise the VPN and potentially interfere with protected traffic.\n\nThe Firebox uses an SSL VPN client for Management Tunnels and BOVPN-Over-TLS. It is not affected by this vulnerability.\n\nFor this attack to succeed, a specially crafted packet is sent to the victim. When the crafted packet contains the correct IP, the vulnerable system will respond with a reset. The Firebox does not respond to this packet no matter if the virtual IP address is correct or not.\n\nWhile the vulnerability does not affect WatchGuard devices, it could still compromise VPN connections to a Firebox if the client OS is vulnerable.","title":"Summary"}],"product_status":{"known_not_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7"]},"cve":"CVE-2019-14899"}]}