PT-2023-4963 · Clario · Clario Vpn Client
Christina Pöpper
+4
·
Published
2023-08-09
·
Updated
2024-05-13
·
CVE-2023-36672
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Clario VPN client versions 5.9.1.1662 and earlier
Description
The issue concerns the insecure configuration of the operating system by the Clario VPN client, which results in traffic to the local network being sent in plaintext outside the VPN tunnel, even when the local network uses a non-RFC1918 IP subnet. This allows an adversary to trick the victim into sending arbitrary IP traffic in plaintext outside the VPN tunnel. The problem is related to the lack of protection for transmitted data.
Recommendations
For Clario VPN client versions 5.9.1.1662 and earlier, update to a version that fixes the insecure configuration issue to prevent traffic from being sent in plaintext outside the VPN tunnel. As a temporary workaround, consider restricting access to the local network to minimize the risk of exploitation.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clario Vpn Client