CVE-2023-36671 is a medium-severity vulnerability affecting the Clario VPN client for macOS (through version 5.9.1.1662). It allows an attacker to deanonymize a user by tricking them into sending plaintext traffic to the VPN server's IP address, bypassing the VPN tunnel. The attack requires user interaction and has high impact on confidentiality and integrity, but no known public exploits or active exploitation have been observed, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.9.1.1662CPE matchmatch criteria | cpe:2.3:a:clario:vpn:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.