VDB
BDU%3A2024-03571
BDU%3A2024-03571
PUBLISHED
CVSS 7.5 HIGH
Уязвимость реализации протокола DHCP, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю манипулировать маршрутами для перенаправления VPN-трафика
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Microsoft Corp, Apple Inc., ООО «НЦПР» | Linux, Windows, MacOS, iOS, МСВСфера |
Timeline
- May 13, 2024 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-pose/ url
- https://datatracker.ietf.org/doc/html/rfc2131#section-7 url
- https://datatracker.ietf.org/doc/html/rfc3442#section-7 url
- https://issuetracker.google.com/issues/263721377 url
- https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ url
- https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic url
- https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision url
- https://news.ycombinator.com/item?id=40279632 url
- https://news.ycombinator.com/item?id=40284111 url
- https://tunnelvisionbug.com/ url
- https://www.agwa.name/blog/post/hardening_openvpn_for_def_con url
- https://www.leviathansecurity.com/research/tunnelvision url
- https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability url
- https://errata.msvsphere-os.ru/definition/9/INFCESA-2025:0006?lang=ru url