Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-3661

Published: May 9, 2024Last modified: June 18, 2025

Description

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

Severity score breakdown

ParameterValue
Base score7.6
Attack VectorADJACENT_NETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Notes

other VPN-providing packages may be affected

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSwireguard-toolsUnknown (1.0.20210914-r1)
Streamwireguard-toolsUnknown (1.0.20210914-r1)

References

ON THIS PAGE