{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"CVE-2024-3661 Impact of TunnelVision Vulnerability","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2024-00009","status":"final","version":"18","initial_release_date":"2024-06-07T00:25:31+00:00","current_release_date":"2026-07-28T01:31:09.105424+00:00","revision_history":[{"date":"2024-06-07T00:25:31+00:00","number":"18","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2024-00009"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2024-3661"}],"notes":[{"category":"summary","text":"Researchers at Leviathan Security discovered VPN clients that rely on routes to redirect traffic can be forced to leak traffic over the physical interface when the endpoint processes a DHCP option 121 message from a rogue DHCP server. An attacker on the same local network can exploit this vulnerability to divert traffic out of the tunnel, allowing them to disrupt and potentially read or modify unencrypted connections. This vulnerability does not allow an attacker to read encrypted traffic.\n\nThe WatchGuard Mobile VPN with SSL and IPSEC Mobile VPN clients for Windows and macOS use the endpoint computer’s route table to direct traffic through the tunnel. Modifications to the endpoint computer's route table, such as those introduced via the scenario described in TunnelVision, could impact VPN traffic routing.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"IPSec VPN Client (NCP) (Windows, macOS)","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"IPSec VPN Client (NCP) (Windows, macOS) all versions","product_id":"CSAFPID-d969168a-b004-4c55-afbb-fd44d62472ed-macos-windows"}}]},{"category":"product_name","name":"Mobile VPN with SSL Client (Windows, macOS)","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Mobile VPN with SSL Client (Windows, macOS) all versions","product_id":"CSAFPID-f1b47ef4-8bf7-4495-ae0f-f8a8ab368049-macos-windows"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"Researchers at Leviathan Security discovered VPN clients that rely on routes to redirect traffic can be forced to leak traffic over the physical interface when the endpoint processes a DHCP option 121 message from a rogue DHCP server. An attacker on the same local network can exploit this vulnerability to divert traffic out of the tunnel, allowing them to disrupt and potentially read or modify unencrypted connections. This vulnerability does not allow an attacker to read encrypted traffic.\n\nThe WatchGuard Mobile VPN with SSL and IPSEC Mobile VPN clients for Windows and macOS use the endpoint computer’s route table to direct traffic through the tunnel. Modifications to the endpoint computer's route table, such as those introduced via the scenario described in TunnelVision, could impact VPN traffic routing.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-d969168a-b004-4c55-afbb-fd44d62472ed-macos-windows","CSAFPID-f1b47ef4-8bf7-4495-ae0f-f8a8ab368049-macos-windows"]},"cve":"CVE-2024-3661"}]}