CVE-2024-3661: DHCP routing options can manipulate interface-based VPN traffic
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3661?
CVE-2024-3661 is considered a high severity vulnerability that can lead to the leakage of VPN traffic.
How do I fix CVE-2024-3661?
To mitigate CVE-2024-3661, it is recommended to update affected software to the latest available versions that address this vulnerability.
What software is affected by CVE-2024-3661?
CVE-2024-3661 affects various versions of Fortinet FortiClient, Cisco AnyConnect, Palo Alto Networks GlobalProtect, F5 BIG-IP Access Policy Manager, and more.
What type of attack does CVE-2024-3661 involve?
CVE-2024-3661 involves an attacker on the same local network using rogue DHCP servers to manipulate routing tables.
Can CVE-2024-3661 lead to data exposure?
Yes, CVE-2024-3661 can potentially lead to data exposure due to the leakage of VPN traffic over unsecured networks.