CVE-2024-3661
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
- Affected products
- Almalinux, Dhcp, Red Hat, Rocky Linux
- Fortinet Forticlient
- < 7.2.5, 7.4.0
- CVSS 3.1
- 7.6 HIGH
- EPSS
- 4.1% (90th percentile)
- Weakness
- CWE-501, CWE-306
- NVD status
- Analyzed
- Published
- 2024-05-06
CVE-2024-3661 at NVD
No indexed exploits for CVE-2024-3661 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-3661 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.