Page MenuHomeVyOS Platform

openNHRP: Auth token leak via Error Indication Authentication Extension
Closed, ResolvedPublic

Description

When the authentication check at nhrp_packet.c:817-832 fails, the daemon sends an Error Indication reply via nhrp_packet_send_error(). The error reply goes through nhrp_packet_route_and_send() which unconditionally inserts the interface's auth_token (plaintext shared secret) into the Authentication extension at lines 1105-1112.
The error reply is routed to src_protocol_address of the attacker's packet via peer-table lookup. If a peer entry exists for the attacker's claimed protocol address (from spoke registration, static map, or dynamic-map), the reply — containing the plaintext secret — is sent to that peer's NBMA address

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability

Event Timeline

RC changed the task status from Open to In progress.
RC triaged this task as High priority.
RC created this object in space Restricted Space.
RC created this object with visibility "Administrators".
RC created this object with edit policy "Administrators".
RC shifted this object from the Restricted Space space to the S1 VyOS Public space.May 21 2026, 12:38 PM
Viacheslav changed the visibility from "Administrators" to "Public (No Login Required)".
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.