Skip to content

TunnelVision - decloaking VPNs using DHCP

High
M0dEx published GHSA-hqmp-g7ph-x543 May 6, 2024

Package

cargo quincy (Rust)

Affected versions

*

Patched versions

None

Description

A new decloaking technique for nearly all VPN implementations has been found, which allows attackers to inject entries into the routing tables of unsuspecting victims using DHCP option 121. This allows attackers to redirect traffic, which is supposed to be sent encrypted over the VPN, through the physical interface handling DHCP for the network the victim's computer is connected to, effectively bypassing any and all confidentiality provided by the VPN.

Impact

All users are potentially affected, as this attack vector can be used against any VPN implementation without mitigations in place.

Patches

Currently, there are no existing mitigations employed by Quincy.

Workarounds

Disabling DHCP option 121 in the DHCP client is a potential workaround, as it prevents this kind of attack.

References

https://www.leviathansecurity.com/blog/tunnelvision

Severity

High
8.3
/ 10

CVSS base metrics

Attack vector
Adjacent
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CVE ID

CVE-2024-3661

Weaknesses

No CWEs