CVE-2023-36671

An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel even if this traffic is not generated by the VPN client. This allows an adversary to trick the victim into sending plaintext traffic to the VPN server's IP address and thereby deanonymize the victim. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "ServerIP attack for only traffic to the real IP address of the VPN server" rather than to only Clario.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
clariovpn
𝑥
≤ 5.9.1.1662
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
connman
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
gadmin-openvpn-client
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
gadmin-openvpn-server
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
golang-github-apparentlymart-go-openvpn-mgmt
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
dne
xenial
dne
trusty
dne
kvpnc
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
not-affected
xenial
not-affected
trusty
ignored
l2tp-ipsec-vpn
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
l2tp-ipsec-vpn-daemon
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
libreswan
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
mozillavpn
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
not-affected
focal
dne
bionic
dne
xenial
dne
trusty
dne
n2n
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-fortisslvpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
network-manager-iodine
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-l2tp
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
network-manager-openconnect
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-openvpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-pptp
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-sstp
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
dne
bionic
dne
xenial
dne
trusty
dne
network-manager-strongswan
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
network-manager-vpnc
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
openconnect
oracular
needed
noble
needed
mantic
ignored
lunar
ignored
jammy
needed
focal
needed
bionic
needed
xenial
needed
trusty
ignored
openfortivpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
openvpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
not-affected
pptp-linux
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
quicktun
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
riseup-vpn
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
softether-vpn
oracular
needed
noble
needed
mantic
ignored
lunar
ignored
jammy
needed
focal
dne
bionic
dne
xenial
dne
trusty
dne
sshuttle
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
tinc
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
vpnc
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
wireguard
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
ignored
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
zentyal-openvpn
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored