VOOZH about

URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3661

⇱ NVD - CVE-2024-3661


  1. Vulnerabilities

CVE-2024-3661 Detail

Description

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Exploit  Press/Media Coverage 
https://bst.cisco.com/quickview/bug/CSCwk05814 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Third Party Advisory  Vendor Advisory 
https://datatracker.ietf.org/doc/html/rfc2131#section-7 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Related 
https://datatracker.ietf.org/doc/html/rfc3442#section-7 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Related 
https://fortiguard.fortinet.com/psirt/FG-IR-24-170 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Vendor Advisory 
https://issuetracker.google.com/issues/263721377 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Issue Tracking 
https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Exploit  Press/Media Coverage 
https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Issue Tracking 
https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Third Party Advisory 
https://my.f5.com/manage/s/article/K000139553 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Vendor Advisory 
https://news.ycombinator.com/item?id=40279632 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Issue Tracking 
https://news.ycombinator.com/item?id=40284111 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Issue Tracking 
https://security.paloaltonetworks.com/CVE-2024-3661 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Vendor Advisory 
https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Vendor Advisory 
https://tunnelvisionbug.com/ CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Exploit  Third Party Advisory 
https://www.agwa.name/blog/post/hardening_openvpn_for_def_con CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Related 
https://www.leviathansecurity.com/research/tunnelvision CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Third Party Advisory 
https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Exploit  Press/Media Coverage 
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Mitigation  Third Party Advisory  Vendor Advisory 
https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability CVE, Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government Exploit  Third Party Advisory  Vendor Advisory 

Weakness Enumeration

CWE-ID CWE Name Source
CWE-306 Missing Authentication for Critical Function 👁 cwe source acceptance level
NIST  
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government  
CWE-501 Trust Boundary Violation Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

13 change records found show changes

CVE Modified by CISA-ADP 6/17/2026 3:44:45 AM

Action Type Old Value New Value
Added SSVC
{"timestamp":"2024-05-08T04:00:07.962328Z","id":"CVE-2024-3661","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 6/17/2026 3:44:45 AM

Action Type Old Value New Value
Added Affected
[{"vendor":"IETF","product":"DHCP","defaultStatus":"affected","versions":[{"version":"0","status":"affected"}]}]


Initial Analysis by NIST 1/15/2025 11:50:28 AM

Action Type Old Value New Value
Added CVSS V3.1
NIST AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L


Added CWE
NIST CWE-306


Added CPE Configuration
AND
 OR
 *cpe:2.3:a:citrix:secure_access_client:*:*:*:*:*:*:*:* versions up to (excluding) 24.06.1
 OR
 cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
 cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*


Added CPE Configuration
AND
 OR
 *cpe:2.3:a:citrix:secure_access_client:*:*:*:*:*:*:*:* versions up to (excluding) 24.8.5
 OR
 cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*


Added CPE Configuration
OR
 *cpe:2.3:a:cisco:anyconnect_vpn_client:-:*:*:*:*:*:*:*
 *cpe:2.3:a:cisco:secure_client:-:*:*:*:*:*:*:*


Added CPE Configuration
OR
 *cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 7.2.3 up to (including) 7.2.5
 *cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 15.1.0 up to (including) 15.1.10
 *cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 16.1.0 up to (including) 16.1.5
 *cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 17.1.0 up to (including) 17.1.2


Added CPE Configuration
OR
 *cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:* versions from (including) 6.4.0 up to (excluding) 7.2.5
 *cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* versions from (including) 6.4.0 up to (excluding) 7.2.5
 *cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* versions from (including) 6.4.0 up to (excluding) 7.2.5
 *cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:linux:*:*
 *cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:macos:*:*
 *cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:windows:*:*


Added CPE Configuration
OR
 *cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:iphone_os:*:*
 *cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:linux:*:*
 *cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
 *cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*


Added CPE Configuration
OR
 *cpe:2.3:a:watchguard:ipsec_mobile_vpn_client:*:*:*:*:*:macos:*:*
 *cpe:2.3:a:watchguard:ipsec_mobile_vpn_client:*:*:*:*:*:windows:*:*
 *cpe:2.3:a:watchguard:mobile_vpn_with_ssl:*:*:*:*:*:macos:*:*
 *cpe:2.3:a:watchguard:mobile_vpn_with_ssl:*:*:*:*:*:windows:*:*


Added CPE Configuration
OR
 *cpe:2.3:a:zscaler:client_connector:-:*:*:*:*:windows:*:*
 *cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:* versions up to (excluding) 1.5.1.25
 *cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:* versions from (including) 3.7 up to (excluding) 3.7.0.134
 *cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:* versions up to (excluding) 4.2.0.282


Changed Reference Type
https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ No Types Assigned


https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ Exploit, Press/Media Coverage


Changed Reference Type
https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ No Types Assigned


https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ Exploit, Press/Media Coverage


Changed Reference Type
https://bst.cisco.com/quickview/bug/CSCwk05814 No Types Assigned


https://bst.cisco.com/quickview/bug/CSCwk05814 Third Party Advisory


Changed Reference Type
https://bst.cisco.com/quickview/bug/CSCwk05814 No Types Assigned


https://bst.cisco.com/quickview/bug/CSCwk05814 Third Party Advisory


Changed Reference Type
https://datatracker.ietf.org/doc/html/rfc2131#section-7 No Types Assigned


https://datatracker.ietf.org/doc/html/rfc2131#section-7 Related


Changed Reference Type
https://datatracker.ietf.org/doc/html/rfc2131#section-7 No Types Assigned


https://datatracker.ietf.org/doc/html/rfc2131#section-7 Related


Changed Reference Type
https://datatracker.ietf.org/doc/html/rfc3442#section-7 No Types Assigned


https://datatracker.ietf.org/doc/html/rfc3442#section-7 Related


Changed Reference Type
https://datatracker.ietf.org/doc/html/rfc3442#section-7 No Types Assigned


https://datatracker.ietf.org/doc/html/rfc3442#section-7 Related


Changed Reference Type
https://fortiguard.fortinet.com/psirt/FG-IR-24-170 No Types Assigned


https://fortiguard.fortinet.com/psirt/FG-IR-24-170 Vendor Advisory


Changed Reference Type
https://fortiguard.fortinet.com/psirt/FG-IR-24-170 No Types Assigned


https://fortiguard.fortinet.com/psirt/FG-IR-24-170 Vendor Advisory


Changed Reference Type
https://issuetracker.google.com/issues/263721377 No Types Assigned


https://issuetracker.google.com/issues/263721377 Issue Tracking


Changed Reference Type
https://issuetracker.google.com/issues/263721377 No Types Assigned


https://issuetracker.google.com/issues/263721377 Issue Tracking


Changed Reference Type
https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ No Types Assigned


https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ Exploit, Press/Media Coverage


Changed Reference Type
https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ No Types Assigned


https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ Exploit, Press/Media Coverage


Changed Reference Type
https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic No Types Assigned


https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic Issue Tracking


Changed Reference Type
https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic No Types Assigned


https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic Issue Tracking


Changed Reference Type
https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision No Types Assigned


https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision Third Party Advisory


Changed Reference Type
https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision No Types Assigned


https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision Third Party Advisory


Changed Reference Type
https://my.f5.com/manage/s/article/K000139553 No Types Assigned


https://my.f5.com/manage/s/article/K000139553 Vendor Advisory


Changed Reference Type
https://my.f5.com/manage/s/article/K000139553 No Types Assigned


https://my.f5.com/manage/s/article/K000139553 Vendor Advisory


Changed Reference Type
https://news.ycombinator.com/item?id=40279632 No Types Assigned


https://news.ycombinator.com/item?id=40279632 Issue Tracking


Changed Reference Type
https://news.ycombinator.com/item?id=40279632 No Types Assigned


https://news.ycombinator.com/item?id=40279632 Issue Tracking


Changed Reference Type
https://news.ycombinator.com/item?id=40284111 No Types Assigned


https://news.ycombinator.com/item?id=40284111 Issue Tracking


Changed Reference Type
https://news.ycombinator.com/item?id=40284111 No Types Assigned


https://news.ycombinator.com/item?id=40284111 Issue Tracking


Changed Reference Type
https://security.paloaltonetworks.com/CVE-2024-3661 No Types Assigned


https://security.paloaltonetworks.com/CVE-2024-3661 Vendor Advisory


Changed Reference Type
https://security.paloaltonetworks.com/CVE-2024-3661 No Types Assigned


https://security.paloaltonetworks.com/CVE-2024-3661 Vendor Advisory


Changed Reference Type
https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 No Types Assigned


https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 Vendor Advisory


Changed Reference Type
https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 No Types Assigned


https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 Vendor Advisory


Changed Reference Type
https://tunnelvisionbug.com/ No Types Assigned


https://tunnelvisionbug.com/ Exploit, Third Party Advisory


Changed Reference Type
https://tunnelvisionbug.com/ No Types Assigned


https://tunnelvisionbug.com/ Exploit, Third Party Advisory


Changed Reference Type
https://www.agwa.name/blog/post/hardening_openvpn_for_def_con No Types Assigned


https://www.agwa.name/blog/post/hardening_openvpn_for_def_con Related


Changed Reference Type
https://www.agwa.name/blog/post/hardening_openvpn_for_def_con No Types Assigned


https://www.agwa.name/blog/post/hardening_openvpn_for_def_con Related


Changed Reference Type
https://www.leviathansecurity.com/research/tunnelvision No Types Assigned


https://www.leviathansecurity.com/research/tunnelvision Third Party Advisory


Changed Reference Type
https://www.leviathansecurity.com/research/tunnelvision No Types Assigned


https://www.leviathansecurity.com/research/tunnelvision Third Party Advisory


Changed Reference Type
https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ No Types Assigned


https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ Exploit, Press/Media Coverage


Changed Reference Type
https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ No Types Assigned


https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ Exploit, Press/Media Coverage


Changed Reference Type
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 No Types Assigned


https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 Mitigation, Vendor Advisory


Changed Reference Type
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 No Types Assigned


https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 Mitigation, Vendor Advisory


Changed Reference Type
https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability No Types Assigned


https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability Exploit, Vendor Advisory


Changed Reference Type
https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability No Types Assigned


https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability Exploit, Vendor Advisory


CVE Modified by CVE 11/21/2024 4:30:07 AM

Action Type Old Value New Value
Added Reference
https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/


Added Reference
https://bst.cisco.com/quickview/bug/CSCwk05814


Added Reference
https://datatracker.ietf.org/doc/html/rfc2131#section-7


Added Reference
https://datatracker.ietf.org/doc/html/rfc3442#section-7


Added Reference
https://fortiguard.fortinet.com/psirt/FG-IR-24-170


Added Reference
https://issuetracker.google.com/issues/263721377


Added Reference
https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/


Added Reference
https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic


Added Reference
https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision


Added Reference
https://my.f5.com/manage/s/article/K000139553


Added Reference
https://news.ycombinator.com/item?id=40279632


Added Reference
https://news.ycombinator.com/item?id=40284111


Added Reference
https://security.paloaltonetworks.com/CVE-2024-3661


Added Reference
https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661


Added Reference
https://tunnelvisionbug.com/


Added Reference
https://www.agwa.name/blog/post/hardening_openvpn_for_def_con


Added Reference
https://www.leviathansecurity.com/research/tunnelvision


Added Reference
https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/


Added Reference
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009


Added Reference
https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 7/01/2024 11:15:17 AM

Action Type Old Value New Value
Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://bst.cisco.com/quickview/bug/CSCwk05814 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://fortiguard.fortinet.com/psirt/FG-IR-24-170 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://my.f5.com/manage/s/article/K000139553 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://security.paloaltonetworks.com/CVE-2024-3661 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 [No types assigned]


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/14/2024 11:42:00 AM

Action Type Old Value New Value

CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/08/2024 6:15:49 PM

Action Type Old Value New Value
Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ [No types assigned]


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/08/2024 1:15:07 PM

Action Type Old Value New Value
Changed Description
By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.


DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/07/2024 3:15:08 PM

Action Type Old Value New Value
Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://news.ycombinator.com/item?id=40284111 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.agwa.name/blog/post/hardening_openvpn_for_def_con [No types assigned]


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/07/2024 2:15:08 PM

Action Type Old Value New Value
Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://issuetracker.google.com/issues/263721377 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability [No types assigned]


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/07/2024 2:15:09 AM

Action Type Old Value New Value
Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://news.ycombinator.com/item?id=40279632 [No types assigned]


CVE Modified by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/06/2024 9:15:06 PM

Action Type Old Value New Value
Added CVSS V3.1
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L


Removed CVSS V3.1
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://tunnelvisionbug.com/ [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.leviathansecurity.com/research/tunnelvision [No types assigned]


Removed Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.leviathansecurity.com/blog/tunnelvision


New CVE Received from Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 5/06/2024 3:15:11 PM

Action Type Old Value New Value
Added Description
By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.


Added CVSS V3.1
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L


Added CWE
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government CWE-306


Added CWE
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government CWE-501


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://datatracker.ietf.org/doc/html/rfc2131#section-7 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://datatracker.ietf.org/doc/html/rfc3442#section-7 [No types assigned]


Added Reference
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.leviathansecurity.com/blog/tunnelvision [No types assigned]


Quick Info

CVE Dictionary Entry:
CVE-2024-3661
NVD Published Date:
05/06/2024
NVD Last Modified:
06/17/2026
Source:
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government