CVE Feed

    Dashboard / CVE / CVE-2024-3661

    CVE-2024-3661

    DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

    Published:May 6, 2024
    Last Modified:Jan 15, 2025
    EPS:May 6, 2024
    EPSS Score:0.02136
    CVSS Score:7.6

    Affected Products

    Vendor
    Apple
    Product
    Iphone Os
    Vendor
    Apple
    Product
    Macos
    Vendor
    Cisco
    Product
    Anyconnect Vpn Client
    Vendor
    Cisco
    Product
    Secure Client
    Vendor
    Citrix
    Product
    Secure Access Client
    Vendor
    F5
    Product
    Big-ip Access Policy Manager
    Vendor
    Fortinet
    Product
    Forticlient
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Paloaltonetworks
    Product
    Globalprotect
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Watchguard
    Product
    Ipsec Mobile Vpn Client
    Vendor
    Watchguard
    Product
    Mobile Vpn With Ssl
    Vendor
    Zscaler
    Product
    Client Connector

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High