PT-2023-4448 · Avira · Avira Phantom Vpn
Christina Pöpper
+4
·
Published
2023-08-09
·
Updated
2023-10-31
·
CVE-2023-36673
CVSS v2.0
7.8
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Avira Phantom VPN versions through 2.23.1
Description
An issue was discovered in Avira Phantom VPN where the VPN client insecurely configures the operating system, sending all IP traffic to the VPN server's IP address in plaintext outside the VPN tunnel. This occurs even if the traffic is not generated by the VPN client, and simultaneously uses plaintext DNS to look up the VPN server's IP address. This allows an adversary to trick the victim into sending traffic to arbitrary IP addresses in plaintext outside the VPN tunnel.
Recommendations
For Avira Phantom VPN versions through 2.23.1, update to a version later than 2.23.1 to resolve the issue. As a temporary workaround, consider restricting access to the VPN server's IP address to minimize the risk of exploitation. Avoid using plaintext DNS to look up the VPN server's IP address until the issue is resolved.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avira Phantom Vpn