WGSA-2024-00009

CVE-2024-3661 Impact of TunnelVision Vulnerability

High Published 2024-06-07Updated 2026-07-28

Summary #

Researchers at Leviathan Security discovered VPN clients that rely on routes to redirect traffic can be forced to leak traffic over the physical interface when the endpoint processes a DHCP option 121 message from a rogue DHCP server. An attacker on the same local network can exploit this vulnerability to divert traffic out of the tunnel, allowing them to disrupt and potentially read or modify unencrypted connections. This vulnerability does not allow an attacker to read encrypted traffic.

The WatchGuard Mobile VPN with SSL and IPSEC Mobile VPN clients for Windows and macOS use the endpoint computer’s route table to direct traffic through the tunnel. Modifications to the endpoint computer's route table, such as those introduced via the scenario described in TunnelVision, could impact VPN traffic routing.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2024-3661 DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. 7.6

Product status #

ProductAffectedNot affected
IPSec VPN Client (NCP)
Windows macOS All versions
Mobile VPN with SSL Client
Windows macOS All versions

Solution #

No solution has been published for this advisory.

Workaround #

IPSec Mobile VPN: Use the *Allow All Traffic Through Tunnel* configuration option to route all traffic through the tunnel
Mobile VPN with SSL: Use the *Force all client traffic through the tunnel* configuration option to route all traffic through the tunnel

References #