PT-2025-1235 · Gre6+1 · Gre6+1
Published
2025-01-15
·
Updated
2025-02-05
·
CVE-2024-7595
CVSS v2.0
6.6
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
GRE and GRE6 protocols (RFC2784) (affected versions not specified)
Description
The GRE and GRE6 protocols do not validate or verify the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This can lead to spoofing, access control bypass, and other unexpected network behaviors. It is estimated that over 4 million systems, including VPN servers and home routers, are affected. The issue can be exploited by sending specially crafted packets to vulnerable hosts, leading to anonymous attacks, DoS attacks, DNS spoofing, and access to internal networks and IoT devices.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gre
Gre6