DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Forticlient | Fortinet | 6.4.0 (including) | 7.2.5 (excluding) |
Forticlient | Fortinet | 7.4.0 (including) | 7.4.0 (including) |
Red Hat Enterprise Linux 8 | RedHat | NetworkManager-1:1.40.16-18.el8_10 | * |
Red Hat Enterprise Linux 8 | RedHat | NetworkManager-1:1.40.16-18.el8_10 | * |
Red Hat Enterprise Linux 9 | RedHat | NetworkManager-1:1.48.10-5.el9_5 | * |
Red Hat Enterprise Linux 9 | RedHat | NetworkManager-1:1.48.10-5.el9_5 | * |
Connman | Ubuntu | mantic | * |
Golang-github-apparentlymart-go-openvpn-mgmt | Ubuntu | mantic | * |
Libreswan | Ubuntu | mantic | * |
N2n | Ubuntu | mantic | * |
Network-manager-fortisslvpn | Ubuntu | mantic | * |
Network-manager-iodine | Ubuntu | mantic | * |
Network-manager-l2tp | Ubuntu | mantic | * |
Network-manager-openconnect | Ubuntu | mantic | * |
Network-manager-openvpn | Ubuntu | mantic | * |
Network-manager-pptp | Ubuntu | mantic | * |
Network-manager-sstp | Ubuntu | mantic | * |
Network-manager-strongswan | Ubuntu | mantic | * |
Network-manager-vpnc | Ubuntu | mantic | * |
Openconnect | Ubuntu | mantic | * |
Openfortivpn | Ubuntu | mantic | * |
Openvpn | Ubuntu | mantic | * |
Openvpn | Ubuntu | trusty/esm | * |
Pptp-linux | Ubuntu | mantic | * |
Pptpd | Ubuntu | mantic | * |
Pptpd | Ubuntu | trusty/esm | * |
Quicktun | Ubuntu | mantic | * |
Riseup-vpn | Ubuntu | mantic | * |
Softether-vpn | Ubuntu | mantic | * |
Sshuttle | Ubuntu | mantic | * |
Tinc | Ubuntu | mantic | * |
Vpnc | Ubuntu | mantic | * |
Wireguard | Ubuntu | mantic | * |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.