CVE-2024-3661
published 2024-05-06CVE-2024-3661: DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect…
PriorityP349high7.6CVSS 3.1
AVAACLPRNUINSUCHILAL
EPSS
4.06%
89.5th percentile
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | secure_access_client | < 24.06.1 | 24.06.1 |
| citrix | secure_access_client | < 24.8.5 | 24.8.5 |
| citrix | xenserver | — | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.5 | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.2 | — |
| f5 | big-ip_access_policy_manager | 7.2.3 – 7.2.5 | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 6.4.0 < 7.2.5 | 7.2.5 |
| ietf | dhcp | — | — |
| paloalto | cloud_ngfw | — | — |
| paloalto | globalprotect_app | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| zscaler | client_connector | < 1.5.1.25 | 1.5.1.25 |
| zscaler | client_connector | < 4.2.0.282 | 4.2.0.282 |
| zscaler | client_connector | >= 3.7 < 3.7.0.134 | 3.7.0.134 |
CVSS provenance
nvdv3.17.6HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
osv7.6HIGH
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Cloud Software Group Security Advisory for CVE-2024-3661
vendor_citrix·2024-06-24·CVSS 7.6
CVE-2024-3661 [HIGH] Cloud Software Group Security Advisory for CVE-2024-3661
Cloud Software Group Security Advisory for CVE-2024-3661
CVE References: CVE-2024-3661
Affected Products: XenServer
Severity: High
Palo Alto
Impact of TunnelVision Vulnerability
vendor_paloalto·2024-05-16·CVSS 7.6
CVE-2024-3661 [HIGH] CWE-306 Impact of TunnelVision Vulnerability
Impact of TunnelVision Vulnerability
The Palo Alto Networks Product Security Assurance team has evaluated the TunnelVision vulnerability as it relates to our products. This issue allows an attacker with the ability to send DHCP messages on the same local area network, such as a rogue Wi-Fi network, to leak traffic outside of the GlobalProtect tunnel, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the GlobalProtect tunnel. However, this attack does not enable the attacker to decrypt HTTPS or other encrypted traffic.
Cloud NGFW, PAN-OS, and Prisma Access do not process DHCP option 121 and are therefore unaffected.
GlobalProtect app on Windows and macOS systems with Endpoint Traffic Policy Enforcement enabled are unaffected.
Red Hat
DHCP: DHCP routing options can manipulate interface-based VPN traffic
vendor_redhat·2024-05-06·CVSS 7.6
CVE-2024-3661 [HIGH] CWE-348 DHCP: DHCP routing options can manipulate interface-based VPN traffic
DHCP: DHCP routing options can manipulate interface-based VPN traffic
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic expected to be protected by the VPN.
Statement: This vu
GHSA
GHSA-jcv7-6v4q-4m7x: By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121)
ghsa_unreviewed·2024-05-06
CVE-2024-3661 [HIGH] CWE-306 GHSA-jcv7-6v4q-4m7x: By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121)
By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.
OSV
CVE-2024-3661: DHCP can add routes to a client’s routing table via the classless static route option (121)
osv·2024-05-06·CVSS 7.6
CVE-2024-3661 [HIGH] CVE-2024-3661: DHCP can add routes to a client’s routing table via the classless static route option (121)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-3661 dhcpcd: DHCP routing options can manipulate interface-based VPN traffic [epel-all]
bugzilla·2024-10-24·CVSS 7.6
CVE-2024-3661 [HIGH] CVE-2024-3661 dhcpcd: DHCP routing options can manipulate interface-based VPN traffic [epel-all]
CVE-2024-3661 dhcpcd: DHCP routing options can manipulate interface-based VPN traffic [epel-all]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2320141
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Following up on:
https://bugzilla.redhat.com/show_bug.cgi?id=2320141#c2
~~~
This is expected to happen with DHCP protocol:
https://datatracker.ietf.org/doc/html/rfc2131#section-7
~~~
and https://bugzilla.redhat.com/show_bug.cgi?id=2320865#c1
~~~
Mitigation at network or VPN level is appropriate, this is not being treated as a bu
Bugzilla
CVE-2024-3661 DHCP: DHCP routing options can manipulate interface-based VPN traffic
bugzilla·2024-10-21·CVSS 7.6
CVE-2024-3661 [HIGH] CVE-2024-3661 DHCP: DHCP routing options can manipulate interface-based VPN traffic
CVE-2024-3661 DHCP: DHCP routing options can manipulate interface-based VPN traffic
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.4 Extended Update Support
Via RHSA-2025:16411 https://access.redhat.com/errata/RHSA-2025:16411
Zscaler
CVE-2026-20131: Analysis of FMC RCE | ThreatLabz
blogs_zscaler·2026-03-23·CVSS 10.0
[CRITICAL] CVE-2026-20131: Analysis of FMC RCE | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
CVE-2024-38856 | ThreatLabz
blogs_zscaler·2024-08-12·CVSS 9.1
[CRITICAL] CVE-2024-38856 | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
CVE-2024-6387 & CVE-2024-6409 | ThreatLabz
blogs_zscaler·2024-08-05·CVSS 8.1
[HIGH] CVE-2024-6387 & CVE-2024-6409 | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bleepingcomputer
New attack leaks VPN traffic using rogue DHCP servers
blogs_bleepingcomputer·2024-05-07·CVSS 7.6
[HIGH] New attack leaks VPN traffic using rogue DHCP servers
## New attack leaks VPN traffic using rogue DHCP servers
## Bill Toulas
"Our technique is to run a DHCP server on the same network as a targeted VPN user and to also set our DHCP configuration to use itself as a gateway," reads the report .
"When the traffic hits our gateway, we use traffic forwarding rules on the DHCP server to pass traffic through to a legitimate gateway while we snoop on it."
The issue lies in DHCP's lack of an authentication mechanism for incoming messages that could manipulate routes, and was assigned the vulnerability identifier CVE-2024-3661 .
The security researchers note that this vulnerability has been available for exploitation by bad actors since at least 2002, but there are no known cases of active exploitation in the wild.
Leviathan has informed many of
Zscaler
CVE-2024-3661 | ThreatLabz
blogs_zscaler·2024-05-07·CVSS 7.6
[HIGH] CVE-2024-3661 | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Dark Deceptions in DHCP: Dismantling Network Defenses
arxiv_fulltext·2025-12-08·CVSS 7.6
[HIGH] Dark Deceptions in DHCP: Dismantling Network Defenses
## Abstract
This paper explores vulnerabilities in the Dynamic Host Configuration Protocol (DHCP) and their implications on the Confidentiality, Integrity, and Availability (CIA) Triad. Through an analysis of various attacks, including DHCP Starvation, Rogue DHCP Servers, Replay Attacks, and TunnelVision exploits, the paper provides a taxonomic classification of threats, assesses risks, and proposes appropriate controls. The discussion also highlights the dangers of VPN decloaking through DHCP exploits and underscores the importance of safeguarding network infrastructures. By bringing awareness to the TunnelVision exploit, this paper aims to mitigate risks associated with these prevalent vulnerabilities.
IEEEkeywords
DHCP Vulnerabilities,
Network Security,
VPN Exploits,
TunnelVision,
Pos
https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/https://bst.cisco.com/quickview/bug/CSCwk05814https://datatracker.ietf.org/doc/html/rfc2131#section-7https://datatracker.ietf.org/doc/html/rfc3442#section-7https://fortiguard.fortinet.com/psirt/FG-IR-24-170https://issuetracker.google.com/issues/263721377https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffichttps://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvisionhttps://my.f5.com/manage/s/article/K000139553https://news.ycombinator.com/item?id=40279632https://news.ycombinator.com/item?id=40284111https://security.paloaltonetworks.com/CVE-2024-3661https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661https://tunnelvisionbug.com/https://www.agwa.name/blog/post/hardening_openvpn_for_def_conhttps://www.leviathansecurity.com/research/tunnelvisionhttps://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerabilityhttps://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/https://bst.cisco.com/quickview/bug/CSCwk05814https://datatracker.ietf.org/doc/html/rfc2131#section-7https://datatracker.ietf.org/doc/html/rfc3442#section-7https://fortiguard.fortinet.com/psirt/FG-IR-24-170https://issuetracker.google.com/issues/263721377https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/https://lowendtalk.com/discussion/188857/a-rogue-dhcp-server-within-your-network-can-and-will-hijack-your-vpn-traffichttps://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvisionhttps://my.f5.com/manage/s/article/K000139553https://news.ycombinator.com/item?id=40279632https://news.ycombinator.com/item?id=40284111https://security.paloaltonetworks.com/CVE-2024-3661https://support.citrix.com/article/CTX677069/cloud-software-group-security-advisory-for-cve20243661https://tunnelvisionbug.com/https://www.agwa.name/blog/post/hardening_openvpn_for_def_conhttps://www.leviathansecurity.com/research/tunnelvisionhttps://www.theregister.com/2024/05/07/vpn_tunnelvision_dhcp/https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00009https://www.zscaler.com/blogs/security-research/cve-2024-3661-k-tunnelvision-exposes-vpn-bypass-vulnerability
2024-05-06
Published