CVE-2023-35838

The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in the blocking of traffic" rather than to only WireGuard.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.7 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
wireguardwireguard
0.5.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
connman
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
gadmin-openvpn-client
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
gadmin-openvpn-server
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
golang-github-apparentlymart-go-openvpn-mgmt
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
dne
xenial
dne
trusty
dne
kvpnc
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
not-affected
xenial
not-affected
trusty
ignored
l2tp-ipsec-vpn
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
l2tp-ipsec-vpn-daemon
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
libreswan
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
mozillavpn
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
not-affected
focal
dne
bionic
dne
xenial
dne
trusty
dne
n2n
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-fortisslvpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
network-manager-iodine
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-l2tp
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
network-manager-openconnect
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-openvpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-pptp
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-sstp
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
dne
bionic
dne
xenial
dne
trusty
dne
network-manager-strongswan
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-vpnc
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
openconnect
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
needed
xenial
needed
trusty
ignored
openfortivpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
openvpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
not-affected
pptp-linux
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
quicktun
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
riseup-vpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
softether-vpn
oracular
needed
noble
needed
mantic
ignored
lunar
ignored
jammy
needed
focal
dne
bionic
dne
xenial
dne
trusty
dne
sshuttle
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
tinc
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
vpnc
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
wireguard
oracular
ignored
noble
ignored
mantic
ignored
lunar
ignored
jammy
ignored
focal
ignored
bionic
ignored
xenial
ignored
trusty
ignored
zentyal-openvpn
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored