Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7596


Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.


Published

2025-02-05T18:15:29.470

Last Modified

2025-02-06T22:15:39.853

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ietf generic_udp_encapsulation - Yes

References