PT-2023-4448 · Avira · Avira Phantom Vpn

Christina Pöpper

+4

·

Published

2023-08-09

·

Updated

2023-10-31

·

CVE-2023-36673

CVSS v2.0

7.8

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Avira Phantom VPN versions through 2.23.1
Description An issue was discovered in Avira Phantom VPN where the VPN client insecurely configures the operating system, sending all IP traffic to the VPN server's IP address in plaintext outside the VPN tunnel. This occurs even if the traffic is not generated by the VPN client, and simultaneously uses plaintext DNS to look up the VPN server's IP address. This allows an adversary to trick the victim into sending traffic to arbitrary IP addresses in plaintext outside the VPN tunnel.
Recommendations For Avira Phantom VPN versions through 2.23.1, update to a version later than 2.23.1 to resolve the issue. As a temporary workaround, consider restricting access to the VPN server's IP address to minimize the risk of exploitation. Avoid using plaintext DNS to look up the VPN server's IP address until the issue is resolved.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2023-04839
CVE-2023-36673

Affected Products

Avira Phantom Vpn