CVE-2024-7596

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/02/2025
Last modified:
06/02/2025

Description

Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.<br /> <br /> This can be considered similar to CVE-2020-10136.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ietf:generic_udp_encapsulation:-:*:*:*:*:*:*:*