Cato CTRL Threat Brief: CVE-2024-3661 – VPN Vulnerability (“TunnelVision”)
CATO Networks
MAY 23, 2024
Cato Networks is not aware of any malicious exploitation of its ZTNA using this technique. Details of the attack When a VPN client operates, it begins by creating an encrypted version of the original packet received from its virtual network interface. One of the advanced features of DHCP is Option 121, introduced in RFC 3442.
Let's personalize your content