CVE-2024-3661

Description

DHCP can add routes to a clients routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

Risk Information

Base Score
7.6
MODERATE
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
EPSS Score
Exploitation Probability
2.415

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Forticlient (x64) 7.2.4Windows
Multiple Vulnerabilities are affected in Forticlient (x64) 7.4.0Windows
Multiple Vulnerabilities are affected in Forticlient 7.2.4Windows
Multiple Vulnerabilities are affected in Forticlient 7.4.0Windows
NetworkManager-adsl update (ELSA-2025-0288) NetworkManager-adsl-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-bluetooth update (ELSA-2025-0288) NetworkManager-bluetooth-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-cloud-setup update (ELSA-2025-0288) NetworkManager-cloud-setup-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-config-connectivity-oracle update (ELSA-2025-0288) NetworkManager-config-connectivity-oracle-1.40.16-18.0.1.el8_10.noarch.rpmLinux
NetworkManager-config-server update (ELSA-2025-0288) NetworkManager-config-server-1.40.16-18.0.1.el8_10.noarch.rpmLinux
NetworkManager-dispatcher-routing-rules update (ELSA-2025-0288) NetworkManager-dispatcher-routing-rules-1.40.16-18.0.1.el8_10.noarch.rpmLinux
NetworkManager-initscripts-updown update (ELSA-2025-0288) NetworkManager-initscripts-updown-1.40.16-18.0.1.el8_10.noarch.rpmLinux
NetworkManager-libnm update (ELSA-2025-0288) NetworkManager-libnm-1.40.16-18.0.1.el8_10.i686.rpmLinux
NetworkManager-libnm update (ELSA-2025-0288) NetworkManager-libnm-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager update (ELSA-2025-0288) NetworkManager-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-ppp update (ELSA-2025-0288) NetworkManager-ppp-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-team update (ELSA-2025-0288) NetworkManager-team-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-tui update (ELSA-2025-0288) NetworkManager-tui-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-wifi update (ELSA-2025-0288) NetworkManager-wifi-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-wwan update (ELSA-2025-0288) NetworkManager-wwan-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-ovs update (ELSA-2025-0288) NetworkManager-ovs-1.40.16-18.0.1.el8_10.x86_64.rpmLinux
NetworkManager-wwan update (ELSA-2025-0377) NetworkManager-wwan-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-wifi update (ELSA-2025-0377) NetworkManager-wifi-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-tui update (ELSA-2025-0377) NetworkManager-tui-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-team update (ELSA-2025-0377) NetworkManager-team-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-ppp update (ELSA-2025-0377) NetworkManager-ppp-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-ovs update (ELSA-2025-0377) NetworkManager-ovs-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-libnm update (ELSA-2025-0377) NetworkManager-libnm-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-libnm update (ELSA-2025-0377) NetworkManager-libnm-1.48.10-5.0.1.el9_5.i686.rpmLinux
NetworkManager-initscripts-updown update (ELSA-2025-0377) NetworkManager-initscripts-updown-1.48.10-5.0.1.el9_5.noarch.rpmLinux
NetworkManager-dispatcher-routing-rules update (ELSA-2025-0377) NetworkManager-dispatcher-routing-rules-1.48.10-5.0.1.el9_5.noarch.rpmLinux
NetworkManager-config-server update (ELSA-2025-0377) NetworkManager-config-server-1.48.10-5.0.1.el9_5.noarch.rpmLinux
NetworkManager-config-connectivity-oracle update (ELSA-2025-0377) NetworkManager-config-connectivity-oracle-1.48.10-5.0.1.el9_5.noarch.rpmLinux
NetworkManager-cloud-setup update (ELSA-2025-0377) NetworkManager-cloud-setup-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-bluetooth update (ELSA-2025-0377) NetworkManager-bluetooth-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager-adsl update (ELSA-2025-0377) NetworkManager-adsl-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
NetworkManager update (ELSA-2025-0377) NetworkManager-1.48.10-5.0.1.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-wwan-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-wifi-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-tui-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-team-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-ppp-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-ovs-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-libnm-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-libnm-1.48.10-5.el9_5.i686.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-initscripts-updown-1.48.10-5.el9_5.noarch.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-dispatcher-routing-rules-1.48.10-5.el9_5.noarch.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-config-server-1.48.10-5.el9_5.noarch.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-config-connectivity-redhat-1.48.10-5.el9_5.noarch.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-cloud-setup-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-bluetooth-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-adsl-1.48.10-5.el9_5.x86_64.rpmLinux
Security and bug fixes for NetworkManager (RLSA-2025:0377) NetworkManager-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-adsl-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-bluetooth-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-cloud-setup-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-config-connectivity-redhat-1.40.16-18.el8_10.noarch.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-config-server-1.40.16-18.el8_10.noarch.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-dispatcher-routing-rules-1.40.16-18.el8_10.noarch.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-initscripts-updown-1.40.16-18.el8_10.noarch.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-libnm-1.40.16-18.el8_10.i686.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-libnm-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-ovs-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-ppp-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-team-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-tui-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-wifi-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Bug fix of NetworkManager NetworkManager-wwan-1.40.16-18.el8_10.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-adsl-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-bluetooth-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-cloud-setup-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-config-connectivity-redhat-1.48.10-5.el9_5.noarch.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-config-server-1.48.10-5.el9_5.noarch.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-dispatcher-routing-rules-1.48.10-5.el9_5.noarch.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-initscripts-updown-1.48.10-5.el9_5.noarch.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-libnm-1.48.10-5.el9_5.i686.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-libnm-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-ovs-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-ppp-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-team-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-tui-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-wifi-1.48.10-5.el9_5.x86_64.rpmLinux
Moderate: Security and bug fixes for NetworkManager NetworkManager-wwan-1.48.10-5.el9_5.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-wwan-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-wifi-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-tui-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-team-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-ppp-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-ovs-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-libnm-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-libnm-1.40.16-18.el8_10.i686.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-initscripts-updown-1.40.16-18.el8_10.noarch.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-dispatcher-routing-rules-1.40.16-18.el8_10.noarch.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-config-server-1.40.16-18.el8_10.noarch.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-config-connectivity-redhat-1.40.16-18.el8_10.noarch.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-cloud-setup-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-bluetooth-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-adsl-1.40.16-18.el8_10.x86_64.rpmLinux
Bug fix of NetworkManager (RLSA-2025:0288) NetworkManager-1.40.16-18.el8_10.x86_64.rpmLinux
Missing Authentication for Critical Function Vulnerability (CVE-2024-3661)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234