Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7595


GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.


Published

2025-02-05T18:15:29.360

Last Modified

2025-02-06T22:15:39.717

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ietf generic_routing_encapsulation - Yes
Application ietf generic_routing_encapsulation6 - Yes

References