Vulnerability Details CVE-2024-7595
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 83.3%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-7595
-
cpe:2.3:a:ietf:generic_routing_encapsulation6:-
-
cpe:2.3:a:ietf:generic_routing_encapsulation:-