CVE-2025-23018

IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ietf:ipv6:-:*:*:*:*:*:*:*

History

29 Jan 2025, 18:01

Type Values Removed Values Added
Summary
  • (es) La tunelización de IPv4 en IPv6 e IPv6 en IPv6 (RFC 2473) no requiere la validación o verificación del origen de un paquete de red, lo que permite a un atacante falsificar y enrutar tráfico arbitrario a través de una interfaz de red expuesta. Este es un problema similar a CVE-2020-10136.
First Time Ietf
Ietf ipv6
CPE cpe:2.3:a:ietf:ipv6:-:*:*:*:*:*:*:*
CWE NVD-CWE-Other
References () https://datatracker.ietf.org/doc/html/rfc2473 - () https://datatracker.ietf.org/doc/html/rfc2473 - Technical Description
References () https://papers.mathyvanhoef.com/usenix2025-tunnels.pdf - () https://papers.mathyvanhoef.com/usenix2025-tunnels.pdf - Technical Description
References () https://www.top10vpn.com/research/tunneling-protocol-vulnerability/ - () https://www.top10vpn.com/research/tunneling-protocol-vulnerability/ - Technical Description

14 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 20:15

Updated : 2025-01-29 18:01


NVD link : CVE-2025-23018

Mitre link : CVE-2025-23018

CVE.ORG link : CVE-2025-23018


JSON object : View

Products Affected

ietf

  • ipv6
CWE
CWE-940

Improper Verification of Source of a Communication Channel

NVD-CWE-Other