← Back

CVE-2024-7596

nvd nist
Published: Feb 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 2.2 / Impact: 3.7
Source: NVD

Description

Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.

Affected (1)

1 product
Generic Udp Encapsulation
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (3)

Source: cret@cert.org
Technical DescriptionRelated
Source: cret@cert.org
Technical DescriptionRelated
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.