Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
History

Thu, 13 Feb 2025 01:00:00 +0000


Thu, 06 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Thu, 06 Feb 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Ietf
Ietf generic Udp Encapsulation
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:ietf:generic_udp_encapsulation:-:*:*:*:*:*:*:*
Vendors & Products Ietf
Ietf generic Udp Encapsulation
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L'}


Wed, 05 Feb 2025 17:45:00 +0000

Type Values Removed Values Added
Description An insecure configuration flaw was found in the Generic UDP Encapsulation Protocol. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls. Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
Title networkmanager: UDP encapsulation protocol excessive trust Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet
References

Fri, 17 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
Description An insecure configuration flaw was found in the Generic UDP Encapsulation Protocol. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Title networkmanager: UDP encapsulation protocol excessive trust
Weaknesses CWE-348
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L'}

threat_severity

Low


cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-02-06T21:24:39.110Z

Reserved: 2024-08-07T20:17:30.815Z

Link: CVE-2024-7596

cve-icon Vulnrichment

Updated: 2025-02-05T18:48:06.899Z

cve-icon NVD

Status : Modified

Published: 2025-02-05T18:15:29.470

Modified: 2025-02-06T22:15:39.853

Link: CVE-2024-7596

cve-icon Redhat

Severity : Low

Publid Date: 2025-01-14T12:00:00Z

Links: CVE-2024-7596 - Bugzilla