CVE-2024-7595

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/02/2025
Last modified:
06/02/2025

Description

GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.<br /> <br /> This can be considered similar to CVE-2020-10136.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ietf:generic_routing_encapsulation:-:*:*:*:*:*:*:*
cpe:2.3:a:ietf:generic_routing_encapsulation6:-:*:*:*:*:*:*:*