CVE-2023-35838

EUVD-2023-39833
The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in the blocking of traffic" rather than to only WireGuard.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.7 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
wireguardwireguard
0.5.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
connman
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
gadmin-openvpn-client
bionic
not-affected
focal
not-affected
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
not-affected
gadmin-openvpn-server
bionic
not-affected
focal
not-affected
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
not-affected
golang-github-apparentlymart-go-openvpn-mgmt
bionic
dne
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
kvpnc
bionic
not-affected
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
not-affected
l2tp-ipsec-vpn
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
dne
l2tp-ipsec-vpn-daemon
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
dne
libreswan
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
mozillavpn
bionic
dne
focal
dne
jammy
not-affected
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
n2n
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-fortisslvpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
network-manager-iodine
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-l2tp
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
network-manager-openconnect
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-openvpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-pptp
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-sstp
bionic
dne
focal
dne
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
network-manager-strongswan
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-vpnc
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
openconnect
bionic
needed
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
needed
openfortivpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
openvpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
not-affected
xenial
not-affected
pptp-linux
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
quicktun
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
riseup-vpn
bionic
dne
focal
dne
jammy
dne
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
softether-vpn
bionic
dne
focal
dne
jammy
needed
lunar
ignored
mantic
ignored
noble
needed
oracular
needed
trusty
dne
xenial
dne
sshuttle
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
tinc
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
vpnc
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
wireguard
bionic
ignored
focal
ignored
jammy
ignored
lunar
ignored
mantic
ignored
noble
ignored
oracular
ignored
trusty
ignored
xenial
ignored
zentyal-openvpn
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
dne