Логотип exploitDog
bind:"BDU:2024-03571" OR bind:"CVE-2024-3661"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2024-03571" OR bind:"CVE-2024-3661"

Количество 8

Количество 8

fstec логотип

BDU:2024-03571

около 1 года назад

Уязвимость реализации протокола DHCP, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю манипулировать маршрутами для перенаправления VPN-трафика

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2024-3661

около 1 года назад

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2024-3661

около 1 года назад

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2024-3661

около 1 года назад

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
EPSS: Низкий
rocky логотип

RLSA-2025:0288

около 1 месяца назад

Moderate: Bug fix of NetworkManager

EPSS: Низкий
github логотип

GHSA-jcv7-6v4q-4m7x

около 1 года назад

By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-0377

5 месяцев назад

ELSA-2025-0377: Security and bug fixes for NetworkManager (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0288

5 месяцев назад

ELSA-2025-0288: Bug fix of NetworkManager (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-03571

Уязвимость реализации протокола DHCP, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю манипулировать маршрутами для перенаправления VPN-трафика

CVSS3: 7.3
2%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
2%
Низкий
около 1 года назад
redhat логотип
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
2%
Низкий
около 1 года назад
nvd логотип
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
2%
Низкий
около 1 года назад
rocky логотип
RLSA-2025:0288

Moderate: Bug fix of NetworkManager

2%
Низкий
около 1 месяца назад
github логотип
GHSA-jcv7-6v4q-4m7x

By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.

CVSS3: 8.8
2%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-0377

ELSA-2025-0377: Security and bug fixes for NetworkManager (MODERATE)

5 месяцев назад
oracle-oval логотип
ELSA-2025-0288

ELSA-2025-0288: Bug fix of NetworkManager (MODERATE)

5 месяцев назад

Уязвимостей на страницу