High severity7.6NVD Advisory· Published May 6, 2024· Updated Jun 17, 2026
CVE-2024-3661
CVE-2024-3661
Description
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
39- cpe:2.3:a:cisco:anyconnect_vpn_client:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_client:-:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:secure_access_client:*:*:*:*:*:*:*:*Range: <24.06.1
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*+ 5 more
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*range: >=6.4.0,<7.2.5
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*range: >=6.4.0,<7.2.5
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: >=6.4.0,<7.2.5
- cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:linux:*:*
- cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:macos:*:*
- cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:iphone_os:*:*+ 3 more
- cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:iphone_os:*:*
- cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:linux:*:*
- cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*
- cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*
cpe:2.3:a:watchguard:ipsec_mobile_vpn_client:*:*:*:*:*:macos:*:*+ 1 more
- cpe:2.3:a:watchguard:ipsec_mobile_vpn_client:*:*:*:*:*:macos:*:*
- cpe:2.3:a:watchguard:ipsec_mobile_vpn_client:*:*:*:*:*:windows:*:*
cpe:2.3:a:watchguard:mobile_vpn_with_ssl:*:*:*:*:*:macos:*:*+ 1 more
- cpe:2.3:a:watchguard:mobile_vpn_with_ssl:*:*:*:*:*:macos:*:*
- cpe:2.3:a:watchguard:mobile_vpn_with_ssl:*:*:*:*:*:windows:*:*
cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:*range: <1.5.1.25
- cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:*range: <4.2.0.282
- cpe:2.3:a:zscaler:client_connector:-:*:*:*:*:windows:*:*
- osv-coords16 versionspkg:rpm/almalinux/NetworkManagerpkg:rpm/almalinux/NetworkManager-adslpkg:rpm/almalinux/NetworkManager-bluetoothpkg:rpm/almalinux/NetworkManager-cloud-setuppkg:rpm/almalinux/NetworkManager-config-connectivity-redhatpkg:rpm/almalinux/NetworkManager-config-serverpkg:rpm/almalinux/NetworkManager-dispatcher-routing-rulespkg:rpm/almalinux/NetworkManager-initscripts-updownpkg:rpm/almalinux/NetworkManager-libnmpkg:rpm/almalinux/NetworkManager-libnm-develpkg:rpm/almalinux/NetworkManager-ovspkg:rpm/almalinux/NetworkManager-ppppkg:rpm/almalinux/NetworkManager-teampkg:rpm/almalinux/NetworkManager-tuipkg:rpm/almalinux/NetworkManager-wifipkg:rpm/almalinux/NetworkManager-wwan
< 1:1.40.16-18.el8_10+ 15 more
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- (no CPE)range: < 1:1.40.16-18.el8_10
- IETF/DHCPv5Range: 0
Patches
Vulnerability mechanics
References
20- arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/nvdExploitPress/Media Coverage
- krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/nvdExploitPress/Media Coverage
- tunnelvisionbug.comnvdExploitThird Party Advisory
- www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/nvdExploitPress/Media Coverage
- www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerabilitynvdExploitThird Party AdvisoryVendor Advisory
- bst.cisco.com/quickview/bug/CSCwk05814nvdThird Party AdvisoryVendor Advisory
- fortiguard.fortinet.com/psirt/FG-IR-24-170nvdVendor Advisory
- mullvad.net/en/blog/evaluating-the-impact-of-tunnelvisionnvdThird Party Advisory
- my.f5.com/manage/s/article/K000139553nvdVendor Advisory
- security.paloaltonetworks.com/CVE-2024-3661nvdVendor Advisory
- support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661nvdVendor Advisory
- www.leviathansecurity.com/research/tunnelvisionnvdThird Party Advisory
- www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009nvdMitigationThird Party AdvisoryVendor Advisory
- datatracker.ietf.org/doc/html/rfc2131nvdRelated
- datatracker.ietf.org/doc/html/rfc3442nvdRelated
- issuetracker.google.com/issues/263721377nvdIssue Tracking
- lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-trafficnvdIssue Tracking
- news.ycombinator.com/itemnvdIssue Tracking
- news.ycombinator.com/itemnvdIssue Tracking
- www.agwa.name/blog/post/hardening_openvpn_for_def_connvdRelated
News mentions
0No linked articles in our index yet.