CVE-2024-3661
7.6
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Exploitability: 2.8 / Impact: 4.7
Source: NVD
Description
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Affected (26)
Products: Fortinet: Forticlient · Cisco: Anyconnect Vpn Client, Secure Client · Paloaltonetworks: Globalprotect · +4 more
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.4.0 to 7.2.5 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 24.06.1 |
| Running on/with | Platform Versions |
|---|---|
Apple Iphone Os | All versions |
Apple Macos | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 24.8.5 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.1.0 to 15.1.10 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5.1.25 |
Related CWEs
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-501
Trust Boundary Violation
The product mixes trusted and untrusted data in the same data structure or structured message.
References (40)
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitPress/Media Coverage
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party AdvisoryVendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Related
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Related
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Issue Tracking
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitPress/Media Coverage
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Issue Tracking
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Issue Tracking
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Issue Tracking
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Related
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitPress/Media Coverage
Source: 9119a7d8-5eab-497f-8521-727c672e3725
MitigationThird Party AdvisoryVendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Related
Source: af854a3a-2127-422b-91ae-364da2661108
Related
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Related
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVendor Advisory
Timeline
No history available yet.