CVE-2024-3661

DHCP can add routes to a clients routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
cisa-cgCNA
7.6 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
fortinetforticlient
6.4.0 ≤
𝑥
< 7.2.5
fortinetforticlient
6.4.0 ≤
𝑥
< 7.2.5
fortinetforticlient
6.4.0 ≤
𝑥
< 7.2.5
fortinetforticlient
7.4.0
fortinetforticlient
7.4.0
fortinetforticlient
7.4.0
ciscoanyconnect_vpn_client
-
ciscosecure_client
-
paloaltonetworksglobalprotect
*
paloaltonetworksglobalprotect
*
paloaltonetworksglobalprotect
*
citrixsecure_access_client
𝑥
< 24.06.1
citrixsecure_access_client
𝑥
< 24.8.5
f5big-ip_access_policy_manager
7.2.3 ≤
𝑥
≤ 7.2.5
f5big-ip_access_policy_manager
15.1.0 ≤
𝑥
≤ 15.1.10
f5big-ip_access_policy_manager
16.1.0 ≤
𝑥
≤ 16.1.5
f5big-ip_access_policy_manager
17.1.0 ≤
𝑥
≤ 17.1.2
watchguardipsec_mobile_vpn_client
*
watchguardipsec_mobile_vpn_client
*
watchguardmobile_vpn_with_ssl
*
watchguardmobile_vpn_with_ssl
*
zscalerclient_connector
𝑥
< 1.5.1.25
zscalerclient_connector
𝑥
< 4.2.0.282
zscalerclient_connector
3.7 ≤
𝑥
< 3.7.0.134
zscalerclient_connector
-
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
connman
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
gadmin-openvpn-client
plucky
dne
oracular
dne
noble
dne
mantic
dne
jammy
dne
focal
deferred
bionic
deferred
xenial
deferred
gadmin-openvpn-server
plucky
dne
oracular
dne
noble
dne
mantic
dne
jammy
dne
focal
deferred
bionic
deferred
xenial
deferred
golang-github-apparentlymart-go-openvpn-mgmt
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
kvpnc
plucky
dne
oracular
dne
noble
dne
mantic
dne
jammy
dne
focal
dne
bionic
deferred
xenial
deferred
libreswan
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
mozillavpn
plucky
dne
oracular
dne
noble
dne
mantic
dne
jammy
deferred
focal
dne
n2n
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
network-manager-fortisslvpn
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
network-manager-iodine
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
network-manager-l2tp
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
network-manager-openconnect
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
network-manager-openvpn
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
network-manager-pptp
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
network-manager-sstp
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
dne
network-manager-strongswan
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
network-manager-vpnc
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
openconnect
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
openfortivpn
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
openvpn
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
trusty
deferred
pptp-linux
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
pptpd
plucky
dne
oracular
dne
noble
dne
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
trusty
deferred
quicktun
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
riseup-vpn
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
dne
focal
dne
softether-vpn
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
dne
sshuttle
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
tinc
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
vpnc
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
wireguard
plucky
deferred
oracular
deferred
noble
deferred
mantic
ignored
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
References