logo

New TunnelVision Attack Allows Hijacking of VPN Traffic via DHCP Manipulation

ID: e61c2dca-d46e-502a-8851-5200e740b12a

STIX ID: report--e61c2dca-d46e-502a-8851-5200e740b12a

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-09

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

TunnelVision (CVE-2024-3661) is a VPN-bypass technique where an attacker-operated DHCP server leverages DHCP option 121 to install routes that redirect VPN traffic outside the encrypted tunnel, enabling interception or modification of traffic; it affects major OSes supporting option 121 (Windows, Linux, macOS, iOS) and VPNs that rely on routing for security, has a CVSS of 7.6, and mitigations include DHCP snooping, ARP protections, port security, and network namespaces on Linux.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.