216.73.217.22

CVE-2024-3661

· Published 06/05/2024 19:15 · Modified 06/05/2024 19:53

Labels: CVE-2024-3661 2024-05-069119a7d8-5eab-497f-8521-727c672e3725CVE-2024-3661CWE-306

Essential information

Published
06/05/2024 19:15
Modified
06/05/2024 19:53
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

CVSS metrics

Description

By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

References