CVE Vulnerabilities

CVE-2023-35838

Externally Controlled Reference to a Resource in Another Sphere

Published: Aug 09, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to LocalNet attack resulting in the blocking of traffic rather than to only WireGuard.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Wireguard Wireguard 0.5.3 (including) 0.5.3 (including)
Connman Ubuntu bionic *
Connman Ubuntu lunar *
Connman Ubuntu trusty *
Connman Ubuntu xenial *
Gadmin-openvpn-client Ubuntu bionic *
Gadmin-openvpn-client Ubuntu trusty *
Gadmin-openvpn-client Ubuntu xenial *
Gadmin-openvpn-server Ubuntu bionic *
Gadmin-openvpn-server Ubuntu trusty *
Gadmin-openvpn-server Ubuntu xenial *
Golang-github-apparentlymart-go-openvpn-mgmt Ubuntu lunar *
Kvpnc Ubuntu bionic *
Kvpnc Ubuntu trusty *
Kvpnc Ubuntu xenial *
L2tp-ipsec-vpn Ubuntu trusty *
L2tp-ipsec-vpn-daemon Ubuntu trusty *
Libreswan Ubuntu bionic *
Libreswan Ubuntu lunar *
N2n Ubuntu bionic *
N2n Ubuntu lunar *
N2n Ubuntu trusty *
N2n Ubuntu xenial *
Network-manager-fortisslvpn Ubuntu bionic *
Network-manager-fortisslvpn Ubuntu lunar *
Network-manager-iodine Ubuntu bionic *
Network-manager-iodine Ubuntu lunar *
Network-manager-iodine Ubuntu trusty *
Network-manager-iodine Ubuntu xenial *
Network-manager-l2tp Ubuntu bionic *
Network-manager-l2tp Ubuntu lunar *
Network-manager-openconnect Ubuntu bionic *
Network-manager-openconnect Ubuntu lunar *
Network-manager-openconnect Ubuntu trusty *
Network-manager-openconnect Ubuntu xenial *
Network-manager-openvpn Ubuntu bionic *
Network-manager-openvpn Ubuntu lunar *
Network-manager-openvpn Ubuntu trusty *
Network-manager-openvpn Ubuntu xenial *
Network-manager-pptp Ubuntu bionic *
Network-manager-pptp Ubuntu lunar *
Network-manager-pptp Ubuntu trusty *
Network-manager-pptp Ubuntu xenial *
Network-manager-sstp Ubuntu lunar *
Network-manager-strongswan Ubuntu bionic *
Network-manager-strongswan Ubuntu lunar *
Network-manager-strongswan Ubuntu trusty *
Network-manager-strongswan Ubuntu xenial *
Network-manager-vpnc Ubuntu bionic *
Network-manager-vpnc Ubuntu lunar *
Network-manager-vpnc Ubuntu trusty *
Network-manager-vpnc Ubuntu xenial *
Openconnect Ubuntu bionic *
Openconnect Ubuntu esm-apps/bionic *
Openconnect Ubuntu esm-apps/xenial *
Openconnect Ubuntu lunar *
Openconnect Ubuntu trusty *
Openconnect Ubuntu xenial *
Openfortivpn Ubuntu bionic *
Openfortivpn Ubuntu lunar *
Openvpn Ubuntu bionic *
Openvpn Ubuntu lunar *
Openvpn Ubuntu trusty *
Openvpn Ubuntu xenial *
Pptp-linux Ubuntu bionic *
Pptp-linux Ubuntu lunar *
Pptp-linux Ubuntu trusty *
Pptp-linux Ubuntu xenial *
Quicktun Ubuntu bionic *
Quicktun Ubuntu lunar *
Riseup-vpn Ubuntu lunar *
Softether-vpn Ubuntu devel *
Softether-vpn Ubuntu esm-apps/noble *
Softether-vpn Ubuntu jammy *
Softether-vpn Ubuntu lunar *
Softether-vpn Ubuntu mantic *
Softether-vpn Ubuntu noble *
Softether-vpn Ubuntu oracular *
Sshuttle Ubuntu bionic *
Sshuttle Ubuntu lunar *
Sshuttle Ubuntu trusty *
Sshuttle Ubuntu xenial *
Tinc Ubuntu bionic *
Tinc Ubuntu lunar *
Tinc Ubuntu trusty *
Tinc Ubuntu xenial *
Vpnc Ubuntu bionic *
Vpnc Ubuntu lunar *
Vpnc Ubuntu trusty *
Vpnc Ubuntu xenial *
Wireguard Ubuntu bionic *
Wireguard Ubuntu devel *
Wireguard Ubuntu esm-apps/bionic *
Wireguard Ubuntu esm-apps/focal *
Wireguard Ubuntu esm-apps/xenial *
Wireguard Ubuntu focal *
Wireguard Ubuntu jammy *
Wireguard Ubuntu lunar *
Wireguard Ubuntu mantic *
Wireguard Ubuntu noble *
Wireguard Ubuntu oracular *
Wireguard Ubuntu trusty *
Wireguard Ubuntu xenial *
Zentyal-openvpn Ubuntu trusty *

References