GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
History

Thu, 13 Feb 2025 01:00:00 +0000


Thu, 06 Feb 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Ietf
Ietf generic Routing Encapsulation
Ietf generic Routing Encapsulation6
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:ietf:generic_routing_encapsulation6:-:*:*:*:*:*:*:*
cpe:2.3:a:ietf:generic_routing_encapsulation:-:*:*:*:*:*:*:*
Vendors & Products Ietf
Ietf generic Routing Encapsulation
Ietf generic Routing Encapsulation6
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L'}


Wed, 05 Feb 2025 17:45:00 +0000

Type Values Removed Values Added
Description An insecure configuration flaw was found in the GRE and GRE6 Protocols. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls. GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
Title networkmanager: GRE & GRE6 protocol excessive trust GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet
References

Fri, 17 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
Description An insecure configuration flaw was found in the GRE and GRE6 Protocols. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Title networkmanager: GRE & GRE6 protocol excessive trust
Weaknesses CWE-348
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L'}

threat_severity

Low


cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-02-06T21:24:58.646Z

Reserved: 2024-08-07T20:16:05.030Z

Link: CVE-2024-7595

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2025-02-05T18:15:29.360

Modified: 2025-02-06T22:15:39.717

Link: CVE-2024-7595

cve-icon Redhat

Severity : Low

Publid Date: 2025-01-14T12:00:00Z

Links: CVE-2024-7595 - Bugzilla