New TunnelVision Attack Allows Hijacking of VPN Traffic via DHCP Manipulation
ID: e61c2dca-d46e-502a-8851-5200e740b12a
STIX ID: report--e61c2dca-d46e-502a-8851-5200e740b12a
Feed Name: The Hacker News
Threat Score
TunnelVision (CVE-2024-3661) is a VPN-bypass technique where an attacker-operated DHCP server leverages DHCP option 121 to install routes that redirect VPN traffic outside the encrypted tunnel, enabling interception or modification of traffic; it affects major OSes supporting option 121 (Windows, Linux, macOS, iOS) and VPNs that rely on routing for security, has a CVSS of 7.6, and mitigations include DHCP snooping, ARP protections, port security, and network namespaces on Linux.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
