CVE-2024-3661 Impact of TunnelVision Vulnerability
Summary #
Researchers at Leviathan Security discovered VPN clients that rely on routes to redirect traffic can be forced to leak traffic over the physical interface when the endpoint processes a DHCP option 121 message from a rogue DHCP server. An attacker on the same local network can exploit this vulnerability to divert traffic out of the tunnel, allowing them to disrupt and potentially read or modify unencrypted connections. This vulnerability does not allow an attacker to read encrypted traffic.
The WatchGuard Mobile VPN with SSL and IPSEC Mobile VPN clients for Windows and macOS use the endpoint computer’s route table to direct traffic through the tunnel. Modifications to the endpoint computer's route table, such as those introduced via the scenario described in TunnelVision, could impact VPN traffic routing.
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2024-3661 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. | 7.6 |
Product status #
| Product | Affected | Not affected |
|---|---|---|
| IPSec VPN Client (NCP) | ||
| Windows macOS | All versions | — |
| Mobile VPN with SSL Client | ||
| Windows macOS | All versions | — |
Solution #
No solution has been published for this advisory.