CVE-2024-3661
📛 CVE Title
DHCP routing options can manipulate interface-based VPN traffic
Description
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- cisa-cg
- CVSS severity
- HIGH
- CVSS score
- 7.6 / 10
- CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L- Effective score
- 7.6 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-306,CWE-501 - Reserved
- 2024-04-11
- Published
- 2024-05-06 18:31 UTC
- Last updated
- 2024-08-28 19:09 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/3xxx/CVE-2024-3661.json
- Linked Threat
- CVE-2024-3661 — Impact of TunnelVision Vulnerability
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2024-05-06 19:15:11 UTC
- NVD last modified
- 2025-01-15 16:50:28 UTC
- NVD CVSS v3.1
- 7.6 / 10 HIGH source: 9119a7d8-5eab-497f-8521-727c672e3725
- NVD CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 4.7 / 10
- EPSS score
- 0.0291 (probability of exploitation in next 30 days)
- EPSS percentile
- 86.55% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD / KEV / EPSS data refreshed 2026-05-25 01:18 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-32236 - Assigner
- cisa-cg
- Published
- May 6, 2024, 6:31:21 PM
- Updated
- Aug 28, 2024, 7:09:06 PM
- EUVD base score (CVSS 3.1)
-
7.6 / 10
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L - EUVD-reported EPSS
- 2.9100
- Vendors
- IETF
- Products
-
dhcp (0)dhcp (0)
- Aliases
-
GHSA-jcv7-6v4q-4m7x
ENISA description: DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
EUVD references (20)
- https://datatracker.ietf.org/doc/html/rfc2131#section-7
- https://datatracker.ietf.org/doc/html/rfc3442#section-7
- https://tunnelvisionbug.com/
- https://www.leviathansecurity.com/research/tunnelvision
- https://news.ycombinator.com/item?id=40279632
- https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/
- https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/
- https://issuetracker.google.com/issues/263721377
- https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision
- https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability
- https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic
- https://news.ycombinator.com/item?id=40284111
- https://www.agwa.name/blog/post/hardening_openvpn_for_def_con
- https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/
- https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009
- https://bst.cisco.com/quickview/bug/CSCwk05814
- https://security.paloaltonetworks.com/CVE-2024-3661
- https://fortiguard.fortinet.com/psirt/FG-IR-24-170
- https://my.f5.com/manage/s/article/K000139553
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| IETF | DHCP |
0 (affected)
|
— |
Affected products — CPE 2.3 (24) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:linux:*:*cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:macos:*:*cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:windows:*:*cpe:2.3:a:cisco:anyconnect_vpn_client:-:*:*:*:*:*:*:*cpe:2.3:a:cisco:secure_client:-:*:*:*:*:*:*:*cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:iphone_os:*:*cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:linux:*:*cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*cpe:2.3:a:citrix:secure_access_client:*:*:*:*:*:*:*:*cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*cpe:2.3:a:watchguard:ipsec_mobile_vpn_client:*:*:*:*:*:macos:*:*cpe:2.3:a:watchguard:ipsec_mobile_vpn_client:*:*:*:*:*:windows:*:*cpe:2.3:a:watchguard:mobile_vpn_with_ssl:*:*:*:*:*:macos:*:*cpe:2.3:a:watchguard:mobile_vpn_with_ssl:*:*:*:*:*:windows:*:*cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:*cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:*cpe:2.3:a:zscaler:client_connector:-:*:*:*:*:windows:*:*
Vendor references (20)
References embedded in the original CVE record by the assigning CNA.
- https://datatracker.ietf.org/doc/html/rfc2131#section-7
- https://datatracker.ietf.org/doc/html/rfc3442#section-7
- https://tunnelvisionbug.com/
- https://www.leviathansecurity.com/research/tunnelvision
- https://news.ycombinator.com/item?id=40279632
- https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/
- https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/
- https://issuetracker.google.com/issues/263721377
- https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision
- https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability
- https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic
- https://news.ycombinator.com/item?id=40284111
- https://www.agwa.name/blog/post/hardening_openvpn_for_def_con
- https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/
- https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009
- https://bst.cisco.com/quickview/bug/CSCwk05814
- https://security.paloaltonetworks.com/CVE-2024-3661
- https://fortiguard.fortinet.com/psirt/FG-IR-24-170
- https://my.f5.com/manage/s/article/K000139553
MITRE references (19) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
- https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability
- https://issuetracker.google.com/issues/263721377
- https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/
- https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic
- https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision
- https://news.ycombinator.com/item?id=40279632
- https://news.ycombinator.com/item?id=40284111
- https://security.paloaltonetworks.com/CVE-2024-3661
- https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661
- https://tunnelvisionbug.com/
- https://www.agwa.name/blog/post/hardening_openvpn_for_def_con
- https://www.leviathansecurity.com/research/tunnelvision
- https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009
- https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/
- https://bst.cisco.com/quickview/bug/CSCwk05814
- https://datatracker.ietf.org/doc/html/rfc2131#section-7
- https://datatracker.ietf.org/doc/html/rfc3442#section-7
- https://fortiguard.fortinet.com/psirt/FG-IR-24-170
Web references (13)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://my.f5.com/manage/s/article/K000139553 rapid7:my.f5.com
- https://errata.rockylinux.org/RLSA-2025:0288 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2025:0377 rapid7:errata.rockylinux.org
- https://errata.almalinux.org/9/ALSA-2025-0377.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/8/ALSA-2025-0288.html rapid7:errata.almalinux.org
- http://cwe.mitre.org/data/definitions/306.html rapid7:cwe.mitre.org
- http://cwe.mitre.org/data/definitions/501.html rapid7:cwe.mitre.org
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32236 rapid7:euvd.enisa.europa.eu
- https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-3661 rapid7:services.nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2024-3661 rapid7:www.cve.org
- https://attackerkb.com/topics/CVE-2024-3661 rapid7:attackerkb.com
- https://www.fortiguard.com/psirt/FG-IR-24-170 rapid7:www.fortiguard.com
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3661 rapid7:cve.mitre.org
NVD-tagged references (40)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ 9119a7d8-5eab-497f-8521-727c672e3725 ExploitPress/Media Coverage
- https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ af854a3a-2127-422b-91ae-364da2661108 ExploitPress/Media Coverage
- https://bst.cisco.com/quickview/bug/CSCwk05814 9119a7d8-5eab-497f-8521-727c672e3725 Third Party AdvisoryVendor Advisory
- https://bst.cisco.com/quickview/bug/CSCwk05814 af854a3a-2127-422b-91ae-364da2661108 Third Party AdvisoryVendor Advisory
- https://datatracker.ietf.org/doc/html/rfc2131#section-7 9119a7d8-5eab-497f-8521-727c672e3725 Related
- https://datatracker.ietf.org/doc/html/rfc2131#section-7 af854a3a-2127-422b-91ae-364da2661108 Related
- https://datatracker.ietf.org/doc/html/rfc3442#section-7 9119a7d8-5eab-497f-8521-727c672e3725 Related
- https://datatracker.ietf.org/doc/html/rfc3442#section-7 af854a3a-2127-422b-91ae-364da2661108 Related
- https://fortiguard.fortinet.com/psirt/FG-IR-24-170 9119a7d8-5eab-497f-8521-727c672e3725 Vendor Advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-24-170 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://issuetracker.google.com/issues/263721377 9119a7d8-5eab-497f-8521-727c672e3725 Issue Tracking
- https://issuetracker.google.com/issues/263721377 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ 9119a7d8-5eab-497f-8521-727c672e3725 ExploitPress/Media Coverage
- https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ af854a3a-2127-422b-91ae-364da2661108 ExploitPress/Media Coverage
- https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic 9119a7d8-5eab-497f-8521-727c672e3725 Issue Tracking
- https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision 9119a7d8-5eab-497f-8521-727c672e3725 Third Party Advisory
- https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://my.f5.com/manage/s/article/K000139553 9119a7d8-5eab-497f-8521-727c672e3725 Vendor Advisory
- https://my.f5.com/manage/s/article/K000139553 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://news.ycombinator.com/item?id=40279632 9119a7d8-5eab-497f-8521-727c672e3725 Issue Tracking
- https://news.ycombinator.com/item?id=40279632 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://news.ycombinator.com/item?id=40284111 9119a7d8-5eab-497f-8521-727c672e3725 Issue Tracking
- https://news.ycombinator.com/item?id=40284111 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://security.paloaltonetworks.com/CVE-2024-3661 9119a7d8-5eab-497f-8521-727c672e3725 Vendor Advisory
- https://security.paloaltonetworks.com/CVE-2024-3661 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 9119a7d8-5eab-497f-8521-727c672e3725 Vendor Advisory
- https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://tunnelvisionbug.com/ 9119a7d8-5eab-497f-8521-727c672e3725 ExploitThird Party Advisory
- https://tunnelvisionbug.com/ af854a3a-2127-422b-91ae-364da2661108 ExploitThird Party Advisory
- https://www.agwa.name/blog/post/hardening_openvpn_for_def_con 9119a7d8-5eab-497f-8521-727c672e3725 Related
- https://www.agwa.name/blog/post/hardening_openvpn_for_def_con af854a3a-2127-422b-91ae-364da2661108 Related
- https://www.leviathansecurity.com/research/tunnelvision 9119a7d8-5eab-497f-8521-727c672e3725 Third Party Advisory
- https://www.leviathansecurity.com/research/tunnelvision af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ 9119a7d8-5eab-497f-8521-727c672e3725 ExploitPress/Media Coverage
- https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ af854a3a-2127-422b-91ae-364da2661108 ExploitPress/Media Coverage
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 9119a7d8-5eab-497f-8521-727c672e3725 MitigationThird Party AdvisoryVendor Advisory
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 af854a3a-2127-422b-91ae-364da2661108 MitigationThird Party AdvisoryVendor Advisory
- https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability 9119a7d8-5eab-497f-8521-727c672e3725 ExploitThird Party AdvisoryVendor Advisory
- https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability af854a3a-2127-422b-91ae-364da2661108 ExploitThird Party AdvisoryVendor Advisory
Indicators (1)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cve |
CVE-2024-3661
|
no local data | 2026-05-14 09:34 UTC |
Remediations (8)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blogs.oracle.com
For more information about the Critical Patch Update program, see the security vulnerability remediation practices page located on the Oracle Trust Center.
2026-05-17 13:26 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-05-17 13:26 UTC -
web:federalnewsnetwork.com
CISA this year has already started accelerating the deadlines for agencies to patch software bugs posted to the Known Exploited Vulnerabilities (KEV) catalog.
2026-05-17 13:26 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-17 13:26 UTC -
web:www.bleepingcomputer.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to secure FortiClient Enterprise Management Server (EMS) instances against an actively exploited ...
2026-05-17 13:26 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-17 13:26 UTC -
web:www.microsoft.com
Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.
2026-05-17 13:26 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-17 13:26 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-3661.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-01T20:20:00.420Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://datatracker.ietf.org/doc/html/rfc2131#section-7"
},
{
"tags": [
"x_transferred"
],
"url": "https://datatracker.ietf.org/doc/html/rfc3442#section-7"
},
{
"tags": [
"x_transferred"
],
"url": "https://tunnelvisionbug.com/"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.leviathansecurity.com/research/tunnelvision"
},
{
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=40279632"
},
{
"tags": [
"x_transferred"
],
"url": "https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/"
},
{
"tags": [
"x_transferred"
],
"url": "https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/"
},
{
"tags": [
"x_transferred"
],
"url": "https://issuetracker.google.com/issues/263721377"
},
{
"tags": [
"x_transferred"
],
"url": "https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability"
},
{
"tags": [
"x_transferred"
],
"url": "https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic"
},
{
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=40284111"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.agwa.name/blog/post/hardening_openvpn_for_def_con"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009"
},
{
"tags": [
"x_transferred"
],
"url": "https://bst.cisco.com/quickview/bug/CSCwk05814"
},
{
"tags": [
"x_transferred"
],
"url": "https://security.paloaltonetworks.com/CVE-2024-3661"
},
{
"tags": [
"x_transferred"
],
"url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-170"
},
{
"tags": [
"x_transferred"
],
"url": "https://my.f5.com/manage/s/article/K000139553"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-3661",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-08T04:00:07.962328Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-08-28T19:09:06.995Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "DHCP",
"vendor": "IETF",
"versions": [
{
"status": "affected",
"version": "0"
}
]
}
],
"datePublic": "2002-12-31T01:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "DHCP can add routes to a client\u2019s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN."
}
],
"value": "DHCP can add routes to a client\u2019s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-501",
"description": "CWE-501 Trust Boundary Violation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-07-01T15:04:50.790Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"url": "https://datatracker.ietf.org/doc/html/rfc2131#section-7"
},
{
"url": "https://datatracker.ietf.org/doc/html/rfc3442#section-7"
},
{
"url": "https://tunnelvisionbug.com/"
},
{
"url": "https://www.leviathansecurity.com/research/tunnelvision"
},
{
"url": "https://news.ycombinator.com/item?id=40279632"
},
{
"url": "https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/"
},
{
"url": "https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/"
},
{
"url": "https://issuetracker.google.com/issues/263721377"
},
{
"url": "https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision"
},
{
"url": "https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability"
},
{
"url": "https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic"
},
{
"url": "https://news.ycombinator.com/item?id=40284111"
},
{
"url": "https://www.agwa.name/blog/post/hardening_openvpn_for_def_con"
},
{
"url": "https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/"
},
{
"url": "https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661"
},
{
"url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009"
},
{
"url": "https://bst.cisco.com/quickview/bug/CSCwk05814"
},
{
"url": "https://security.paloaltonetworks.com/CVE-2024-3661"
},
{
"url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-170"
},
{
"url": "https://my.f5.com/manage/s/article/K000139553"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "DHCP routing options can manipulate interface-based VPN traffic",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2024-3661",
"datePublished": "2024-05-06T18:31:21.217Z",
"dateReserved": "2024-04-11T17:24:22.637Z",
"dateUpdated": "2024-08-28T19:09:06.995Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}