Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2024-3661 Details
Description
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:7.6 HIGHVector:CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2024Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-501 | Trust Boundary Violation | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| fortinet forticlient | >= 6.4.0, < 7.2.5 7.4.0 |
CPE
Remediation
| |
| cisco anyconnect vpn client | All versions |
CPE
Remediation
| |
| cisco secure client | All versions |
CPE
Remediation
| |
| paloaltonetworks globalprotect | All versions |
CPE
Remediation
| |
| citrix secure access client | < 24.06.1 < 24.8.5 |
CPE
Remediation
| |
| apple iphone os | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| f5 big-ip access policy manager | >= 7.2.3, <= 7.2.5 >= 15.1.0, <= 15.1.10 >= 16.1.0, <= 16.1.5 >= 17.1.0, <= 17.1.2 |
CPE
Remediation
| |
| watchguard ipsec mobile vpn client | All versions |
CPE
Remediation
| |
| watchguard mobile vpn with ssl | All versions |
CPE
Remediation
| |
| zscaler client connector | < 1.5.1.25 < 4.2.0.282 >= 3.7, < 3.7.0.134 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 1, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 14, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 8, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 8, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 7, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 7, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 7, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 7, 2024 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 6, 2024 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |