Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-jcv7-6v4q-4m7x

около 2 лет назад

By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2024-3661

около 2 лет назад

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2024-3661

около 2 лет назад

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2024-3661

около 2 лет назад

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
EPSS: Низкий
rocky логотип

RLSA-2025:0377

больше 1 года назад

Moderate: Security and bug fixes for NetworkManager

EPSS: Низкий
rocky логотип

RLSA-2025:0288

около 1 года назад

Moderate: Bug fix of NetworkManager

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0377

больше 1 года назад

ELSA-2025-0377: Security and bug fixes for NetworkManager (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0288

больше 1 года назад

ELSA-2025-0288: Bug fix of NetworkManager (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-03571

около 2 лет назад

Уязвимость реализации протокола DHCP, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю манипулировать маршрутами для перенаправления VPN-трафика

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jcv7-6v4q-4m7x

By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.

CVSS3: 8.8
4%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
4%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
4%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVSS3: 7.6
4%
Низкий
около 2 лет назад
rocky логотип
RLSA-2025:0377

Moderate: Security and bug fixes for NetworkManager

4%
Низкий
больше 1 года назад
rocky логотип
RLSA-2025:0288

Moderate: Bug fix of NetworkManager

4%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-0377

ELSA-2025-0377: Security and bug fixes for NetworkManager (MODERATE)

4%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2025-0288

ELSA-2025-0288: Bug fix of NetworkManager (MODERATE)

4%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-03571

Уязвимость реализации протокола DHCP, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю манипулировать маршрутами для перенаправления VPN-трафика

CVSS3: 7.3
4%
Низкий
около 2 лет назад

Уязвимостей на страницу