Vulnerability Report

CVE-2024-3661

Title: Watchguard Mobile Vpn With Ssl Auth Bypass

Auth Bypass

Proof Of Concept

PoC Available for CVE-2024-3661

CWE Category CWE-306
Published Date May 06, 2024
Modified Date Jan 15, 2025
Exploit Status Available
Score 7.6 CVSS v3.1
Exploit Probability (EPSS)
4.06%

Vulnerability Summary

CVE-2024-3661: DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

Impacted Vendors

Reference Links

https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ https://bst.cisco.com/quickview/bug/CSCwk05814 https://datatracker.ietf.org/doc/html/rfc2131#section-7 https://datatracker.ietf.org/doc/html/rfc3442#section-7 https://fortiguard.fortinet.com/psirt/FG-IR-24-170 https://issuetracker.google.com/issues/263721377 https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision https://my.f5.com/manage/s/article/K000139553 https://news.ycombinator.com/item?id=40279632 https://news.ycombinator.com/item?id=40284111 https://security.paloaltonetworks.com/CVE-2024-3661 https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 https://tunnelvisionbug.com/ https://www.agwa.name/blog/post/hardening_openvpn_for_def_con https://www.leviathansecurity.com/research/tunnelvision https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ https://bst.cisco.com/quickview/bug/CSCwk05814 https://datatracker.ietf.org/doc/html/rfc2131#section-7 https://datatracker.ietf.org/doc/html/rfc3442#section-7 https://fortiguard.fortinet.com/psirt/FG-IR-24-170 https://issuetracker.google.com/issues/263721377 https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/ https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision https://my.f5.com/manage/s/article/K000139553 https://news.ycombinator.com/item?id=40279632 https://news.ycombinator.com/item?id=40284111 https://security.paloaltonetworks.com/CVE-2024-3661 https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661 https://tunnelvisionbug.com/ https://www.agwa.name/blog/post/hardening_openvpn_for_def_con https://www.leviathansecurity.com/research/tunnelvision https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/ https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009 https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability
CVSS v3.1
Source Entity [email protected]
Severity HIGH
7.6
Attack Vector
ADJACENT_NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CVSS v3.1
Source Entity 9119a7d8-5eab-497f-8521-727c672e3725
Severity HIGH
7.6
Attack Vector
ADJACENT_NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2024-3661 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/Wh1t3Fox/CVE-2024-3661
View Code
GitHub https://github.com/Roundthe-clock/CVE-2024-3661VPN
View Code
GitHub https://github.com/YardenFadida/CVE-2024-3661_Demo
View Code
MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector ADJACENT_NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected Stack

No specific products linked.