article thumbnail

Cato CTRL Threat Brief: CVE-2024-3661 – VPN Vulnerability (“TunnelVision”)

CATO Networks

The attack requires introducing a rogue DHCP server to the local network. In the case presented in the article, the malicious DHCP server poisons the routing table of its neighbor on the local network. This encrypted packet is then encapsulated within the VPN protocol layer, allowing secure communication with the VPN server.

VPN 52