Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-3661 Details

Description

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:7.6 HIGHVector:CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentExploitPress/Media Coverage
https://bst.cisco.com/quickview/bug/CSCwk05814 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentThird Party AdvisoryVendor Advisory
https://datatracker.ietf.org/doc/html/rfc2131#section-7 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentRelated
https://datatracker.ietf.org/doc/html/rfc3442#section-7 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentRelated
https://fortiguard.fortinet.com/psirt/FG-IR-24-170 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentVendor Advisory

see all 40 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-306Missing Authentication for Critical Function[email protected]
CWE-306Missing Authentication for Critical FunctionCybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
CWE-501Trust Boundary ViolationCybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Affected Products

ProductVersions

Change History

13 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-3661
NVD Published Date:
May 6, 2024
NVD Last Modified:
Jun 17, 2026
Source:
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
CVE-2024-3661 Details - Not Deferred