CVE-2025-24356 describes a UDP amplification vulnerability in fastd, a VPN daemon. This flaw allows an attacker to send small, spoofed UDP packets to fastd instances, triggering a significantly larger handshake response (amplification factor of 12-13x). With a CVSS score of 7.5 (High), this vulnerability poses a significant risk for Distributed Denial of Service (DDoS) attacks against targeted victims. While there is no evidence of active exploitation, public exploit code, or community discussion, the ease of exploitation (network attack vector, low complexity) warrants attention. A fix is available in fastd v23.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.0CPE matchmatch criteria | cpe:2.3:a:fastd_project:fastd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.