CVE-2023-36671

EUVD-2023-40614
An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel even if this traffic is not generated by the VPN client. This allows an adversary to trick the victim into sending plaintext traffic to the VPN server's IP address and thereby deanonymize the victim. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "ServerIP attack for only traffic to the real IP address of the VPN server" rather than to only Clario.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
clariovpn
𝑥
≤ 5.9.1.1662
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
connman
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
gadmin-openvpn-client
bionic
not-affected
focal
not-affected
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
not-affected
gadmin-openvpn-server
bionic
not-affected
focal
not-affected
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
not-affected
golang-github-apparentlymart-go-openvpn-mgmt
bionic
dne
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
kvpnc
bionic
not-affected
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
not-affected
l2tp-ipsec-vpn
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
dne
l2tp-ipsec-vpn-daemon
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
dne
libreswan
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
mozillavpn
bionic
dne
focal
dne
jammy
not-affected
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
n2n
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-fortisslvpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
network-manager-iodine
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-l2tp
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
network-manager-openconnect
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-openvpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-pptp
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-sstp
bionic
dne
focal
dne
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
network-manager-strongswan
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
network-manager-vpnc
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
openconnect
bionic
needed
focal
needed
jammy
needed
lunar
ignored
mantic
ignored
noble
needed
oracular
needed
trusty
ignored
xenial
needed
openfortivpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
openvpn
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
not-affected
xenial
not-affected
pptp-linux
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
quicktun
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
riseup-vpn
bionic
dne
focal
dne
jammy
dne
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
softether-vpn
bionic
dne
focal
dne
jammy
needed
lunar
ignored
mantic
ignored
noble
needed
oracular
needed
trusty
dne
xenial
dne
sshuttle
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
tinc
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
vpnc
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
wireguard
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
ignored
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
zentyal-openvpn
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
dne