← Back

CVE-2024-7595

nvd nist
Published: Feb 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 2.2 / Impact: 3.7
Source: NVD

Description

GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.

Affected (2)

2 products
Generic Routing Encapsulation
Generic Routing Encapsulation6
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions

References (3)

Source: cret@cert.org
Technical DescriptionRelated
Source: cret@cert.org
Technical DescriptionRelated
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.