CVE-2023-35838
Summary
| CVE | CVE-2023-35838 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-09 23:15:00 UTC |
| Updated | 2023-10-31 09:15:00 UTC |
| Description | The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in the blocking of traffic" rather than to only WireGuard. |
Risk And Classification
Problem Types: CWE-610
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WireGuard: fast, modern, secure VPN tunnel | MISC | wireguard.com | |
| Security Advisory | CONFIRM | psirt.global.sonicwall.com | |
| TunnelCrack: Widespread design flaws in VPN clients | MISC | tunnelcrack.mathyvanhoef.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.