PT-2020-14516 · Docker+1 · Docker+1
Sickcodes
·
Published
2020-09-14
·
Updated
2021-07-21
·
CVE-2020-15590
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Private Internet Access (PIA) VPN Client for Linux versions 1.5 through 2.3
Description
A vulnerability in the Private Internet Access (PIA) VPN Client for Linux allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. This occurs when the kill switch is configured to block all inbound and outbound network traffic, but privileged applications can continue sending and receiving network traffic if
net.ipv4.ip forward has been enabled in the system kernel parameters. For instance, a Docker container running on a host with the VPN turned off and the kill switch turned on can continue using the internet, potentially leaking the host IP.Recommendations
For Private Internet Access (PIA) VPN Client for Linux versions 1.5 through 2.3, consider updating to version 2.4.0 or later, which enables policy-based routing by default to direct all forwarded packets to the VPN interface automatically. As a temporary workaround, consider disabling the
net.ipv4.ip forward option in the system kernel parameters to prevent privileged applications from bypassing the kill switch mechanism.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker
Private Internet Access (Pia) Vpn Client For Linux