PT-2025-1234 · Unknown · Ipv6-In-Ipv4 Tunneling

Angelos Beitis

+1

·

Published

2025-01-14

·

Updated

2025-01-29

·

CVE-2025-23019

CVSS v2.0

6.6

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions IPv6-in-IPv4 tunneling (RFC 4213) versions not specified
Description The issue is related to the IPv6-in-IPv4 tunneling protocol, which allows an attacker to spoof and route traffic via an exposed network interface. This can be exploited by a remote attacker to conduct attacks, such as spoofing a trusted object, by sending a specially crafted packet with two IP headers. The vulnerability is associated with insufficient source channel verification in packet tunneling protocols.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-00614
CVE-2025-23019

Affected Products

Ipv6-In-Ipv4 Tunneling