CVE-2024-7595 describes a vulnerability in the GRE and GRE6 protocols, affecting implementations of ietf generic_routing_encapsulation and ietf generic_routing_encapsulation6. The flaw stems from a lack of source validation for network packets, enabling attackers to spoof and route arbitrary traffic through exposed network interfaces. This medium-severity vulnerability (CVSS 6.5) can lead to spoofing, access control bypass, and other network anomalies, with a high attack complexity but no user interaction required. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ietf:generic_routing_encapsulation:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ietf:generic_routing_encapsulation6:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.