CVE-2024-7596
MEDIUMDescription
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
Is your site exposed to CVE-2024-7596?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| ietf | generic_udp_encapsulation |
References
Frequently Asked Questions
What is CVE-2024-7596? +
How severe is CVE-2024-7596? +
What products are affected by CVE-2024-7596? +
How do I check if I'm vulnerable to CVE-2024-7596? +
Related Vulnerabilities
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to …
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, …
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.