Description

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

INFO

Published Date :

2024-05-06T18:31:21.217Z

Last Modified :

2024-08-28T19:09:06.995Z

Source :

cisa-cg
AFFECTED PRODUCTS

The following products are affected by CVE-2024-3661 vulnerability.

Vendors Products
Apple
  • Iphone Os
  • Macos
Cisco
  • Anyconnect Vpn Client
  • Secure Client
Citrix
  • Secure Access Client
F5
  • Big-ip Access Policy Manager
Fortinet
  • Forticlient
Linux
  • Linux Kernel
Paloaltonetworks
  • Globalprotect
Redhat
  • Enterprise Linux
Watchguard
  • Ipsec Mobile Vpn Client
  • Mobile Vpn With Ssl
Zscaler
  • Client Connector
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-3661.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact