{
    "data_version": "4.0",
    "data_type": "CVE",
    "data_format": "MITRE",
    "CVE_data_meta": {
        "ID": "CVE-2024-3661",
        "ASSIGNER": "cve@mitre.org",
        "STATE": "PUBLIC"
    },
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "DHCP can add routes to a client\u2019s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN."
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "CWE-306 Missing Authentication for Critical Function",
                        "cweId": "CWE-306"
                    }
                ]
            },
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "CWE-501 Trust Boundary Violation",
                        "cweId": "CWE-501"
                    }
                ]
            }
        ]
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "vendor_name": "IETF",
                    "product": {
                        "product_data": [
                            {
                                "product_name": "DHCP",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_value": "not down converted",
                                            "x_cve_json_5_version_data": {
                                                "versions": [
                                                    {
                                                        "status": "affected",
                                                        "version": "0"
                                                    }
                                                ],
                                                "defaultStatus": "affected"
                                            }
                                        }
                                    ]
                                }
                            }
                        ]
                    }
                }
            ]
        }
    },
    "references": {
        "reference_data": [
            {
                "url": "https://datatracker.ietf.org/doc/html/rfc2131#section-7",
                "refsource": "MISC",
                "name": "https://datatracker.ietf.org/doc/html/rfc2131#section-7"
            },
            {
                "url": "https://datatracker.ietf.org/doc/html/rfc3442#section-7",
                "refsource": "MISC",
                "name": "https://datatracker.ietf.org/doc/html/rfc3442#section-7"
            },
            {
                "url": "https://tunnelvisionbug.com/",
                "refsource": "MISC",
                "name": "https://tunnelvisionbug.com/"
            },
            {
                "url": "https://www.leviathansecurity.com/research/tunnelvision",
                "refsource": "MISC",
                "name": "https://www.leviathansecurity.com/research/tunnelvision"
            },
            {
                "url": "https://news.ycombinator.com/item?id=40279632",
                "refsource": "MISC",
                "name": "https://news.ycombinator.com/item?id=40279632"
            },
            {
                "url": "https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/",
                "refsource": "MISC",
                "name": "https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/"
            },
            {
                "url": "https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/",
                "refsource": "MISC",
                "name": "https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/"
            },
            {
                "url": "https://issuetracker.google.com/issues/263721377",
                "refsource": "MISC",
                "name": "https://issuetracker.google.com/issues/263721377"
            },
            {
                "url": "https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision",
                "refsource": "MISC",
                "name": "https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision"
            },
            {
                "url": "https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability",
                "refsource": "MISC",
                "name": "https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability"
            },
            {
                "url": "https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic",
                "refsource": "MISC",
                "name": "https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffic"
            },
            {
                "url": "https://news.ycombinator.com/item?id=40284111",
                "refsource": "MISC",
                "name": "https://news.ycombinator.com/item?id=40284111"
            },
            {
                "url": "https://www.agwa.name/blog/post/hardening_openvpn_for_def_con",
                "refsource": "MISC",
                "name": "https://www.agwa.name/blog/post/hardening_openvpn_for_def_con"
            },
            {
                "url": "https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/",
                "refsource": "MISC",
                "name": "https://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/"
            },
            {
                "url": "https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661",
                "refsource": "MISC",
                "name": "https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661"
            },
            {
                "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009",
                "refsource": "MISC",
                "name": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009"
            },
            {
                "url": "https://bst.cisco.com/quickview/bug/CSCwk05814",
                "refsource": "MISC",
                "name": "https://bst.cisco.com/quickview/bug/CSCwk05814"
            },
            {
                "url": "https://security.paloaltonetworks.com/CVE-2024-3661",
                "refsource": "MISC",
                "name": "https://security.paloaltonetworks.com/CVE-2024-3661"
            },
            {
                "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-170",
                "refsource": "MISC",
                "name": "https://fortiguard.fortinet.com/psirt/FG-IR-24-170"
            },
            {
                "url": "https://my.f5.com/manage/s/article/K000139553",
                "refsource": "MISC",
                "name": "https://my.f5.com/manage/s/article/K000139553"
            }
        ]
    },
    "generator": {
        "engine": "Vulnogram 0.1.0-dev"
    },
    "source": {
        "discovery": "UNKNOWN"
    },
    "impact": {
        "cvss": [
            {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
                "version": "3.1"
            }
        ]
    }
}