← Back

CVE-2024-3661

nvd nist
Published: May 6, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Exploitability: 2.8 / Impact: 4.7
Source: NVD

Description

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

Affected (26)

Show all products
1 product
Forticlient
2 products
Anyconnect Vpn Client
Secure Client
Globalprotect
1 product
Secure Access Client
1 product
Big Ip Access Policy Manager
2 products
Ipsec Mobile Vpn Client
Mobile Vpn With Ssl
1 product
Client Connector
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 7.2.5
From 6.4.0 to 7.2.5
From 6.4.0 to 7.2.5
Version 7.4.0
Version 7.4.0
Version 7.4.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
All versions
All versions
All versions
All versions
Configuration D
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 24.06.1
Running on/withPlatform Versions
Apple
Iphone Os
All versions
Apple
Macos
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 24.8.5
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 15.1.0 to 15.1.10
From 16.1.0 to 16.1.5
From 17.1.0 to 17.1.2
From 7.2.3 to 7.2.5
Configuration G
4 vulnerable
Vulnerable SoftwareAffected Versions
Watchguard
All versions
All versions
Watchguard
All versions
All versions
Configuration H
4 vulnerable
Vulnerable SoftwareAffected Versions
Zscaler
Before 1.5.1.25
From 3.7 to 3.7.0.134
Before 4.2.0.282
All versions

References (40)

Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party AdvisoryVendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Related
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Related
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Issue Tracking
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitPress/Media Coverage
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Issue Tracking
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Issue Tracking
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitThird Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Related
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitPress/Media Coverage
Source: 9119a7d8-5eab-497f-8521-727c672e3725
MitigationThird Party AdvisoryVendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Related
Source: af854a3a-2127-422b-91ae-364da2661108
Related
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Related
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVendor Advisory

Timeline

No history available yet.