---
title: No flaws found in OpenVPN software
description: “The issue is more in how the operating system deals with this type of attack in general, rather than anything going wrong in the VPN connection itself,”
image: https://blog.openvpn.net/hubfs/Untitled-design.jpg
---

- [Blog](https://blog.openvpn.net)
- [Announcements](https://blog.openvpn.net/tag/announcements)
- [Cybersecurity](https://blog.openvpn.net/tag/cybersecurity)

# No flaws found in OpenVPN software

Dec 6, 2019 •  2 min read

![](https://blog.openvpn.net/hubfs/Untitled-design.jpg)

Share

- <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.openvpn.net%2Fno-flaws-found-in-openvpn-software%2F&title=No%20flaws%20found%20in%20OpenVPN%20software&summary=%E2%80%9CThe+issue+is+more+in+how+the+operating+system+deals+with+this+type+of+attack+in+general%2C+rather+than+anything+going+wrong+in+the+VPN+connection+itself%2C%E2%80%9D&source=>
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.openvpn.net%2Fno-flaws-found-in-openvpn-software%2F>
- <https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.openvpn.net%2Fno-flaws-found-in-openvpn-software%2F&text=No+flaws+found+in+OpenVPN+software>
- <https://blog.openvpn.net/no-flaws-found-in-openvpn-software/>

By OpenVPN Team

A [research team](https://seclists.org/oss-sec/2019/q4/122)from the University of New Mexico discovered a vulnerability currently being tracked as CVE-2019-14899 which claims that [VPN](https://openvpn.net) connections can be hijacked on Linux and Unix systems. The report mentioned the OpenVPN protocol. As part of good security principles, we are looking into this and any possible attack vectors, however we have found no flaws in the OpenVPN software.

An initial investigation by our security experts, and experts across the globe, reveals that this issue affects all network interfaces, not VPN in particular.

“It doesn't appear to be a flaw in the OpenVPN software, but a flaw in the configuration of the operating system itself. The issue is more in how the operating system deals with this type of attack in general, rather than anything going wrong in the VPN connection itself,” says OpenVPN Access Server Product Manager, Johan Draaisma.

To our knowledge, the vulnerability is only impacting Linux and Unix systems and requires that the attacker has control over your Internet access point and can therefore reach and affect your computer outside of the VPN, in the local network, for example. Based on this, the attack is somewhat limited, and there is no straight-forward way to retrieve unencrypted data from the VPN connection.

“The issue may actually be located in the Linux operating system settings rather than in our software, but given the serious nature of the attack, we are paying close attention and will consider whatever steps are appropriate to ensure OpenVPN remains safe to use on these affected platforms. For now enabling the ‘reverse path filter’ setting in the OS is a good first step to help protect against this attack,” says Draaisma.

OpenVPN Inc. is keeping a close eye on the discussions currently ongoing, and possible solutions. Currently there is no evidence suggesting there is a flaw in the OpenVPN software itself.

[![Get Started Today](https://no-cache.hubspot.com/cta/default/43411546/3d7352c6-482b-41f2-9794-df8fb9ef448b.png)](https://cta-redirect.hubspot.com/cta/redirect/43411546/3d7352c6-482b-41f2-9794-df8fb9ef448b)

## Related posts from OpenVPN

### [![The Leaves May Fall, but OpenVPN is Still on the Rise!](https://blog.openvpn.net/hubfs/Fall%202024%20G2%20Awards%20Blog%20%20(1).png) Announcements Oct 21, 2024 The Leaves May Fall, but OpenVPN is Still on the Rise!](https://blog.openvpn.net/fall-2024-g2-awards)

### [![OpenVPN Freezes Out the Competition with Winter 2025 G2 Awards](https://blog.openvpn.net/hubfs/Winter%20G2%20Awards%20(1).png) Announcements Jan 16, 2025 OpenVPN Freezes Out the Competition with Winter 2025 G2 Awards](https://blog.openvpn.net/winter-2025-g2-awards)

### [![Introducing MCP Gateway: One Front Door for Every AI Agent Your Business Runs](https://blog.openvpn.net/hubfs/cloudconnexa-blog-header-blue.png) Announcements Aug 25, 2026 Introducing MCP Gateway: One Front Door for Every AI Agent Your Business Runs](https://blog.openvpn.net/introducing-mcp-gateway-one-front-door-for-every-ai-agent-your-business-runs)

### Subscribe for Blog Updates

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "OpenVPN Team",
    "url" : "https://blog.openvpn.net/author/openvpn-marketing"
  },
  "dateModified" : "2025-09-02T23:52:47.305Z",
  "datePublished" : "2019-12-06T08:00:00.000Z",
  "headline" : "No flaws found in OpenVPN software",
  "image" : [ "https://blog.openvpn.net/hubfs/Untitled-design.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.openvpn.net/no-flaws-found-in-openvpn-software/",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.openvpn.net/hubfs/Dark=True%20Medium.png"
    },
    "name" : "OpenVPN"
  }
}
```