CVE-2024-3661General(apple / anyconnect_vpn_client)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple anyconnect_vpn_client systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-501

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • anyconnect_vpn_client
  • big-ip_access_policy_manager
  • client_connector
  • forticlient

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
anyconnect_vpn_clientbig-ip_access_policy_managerclient_connectorforticlientglobalprotectiphone_osipsec_mobile_vpn_clientlinux_kernelmacosmobile_vpn_with_ssl

2 versions affected across 12 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-20: 1Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-02-20: 102-2005-27
Signal classification1 categories
General
2100.0%
Full discourse2 posts
  • transilienceai@transilienceai
    General

    @Sh4hdov This differs from CVE-2024-3661, a VPN traffic leak via DHCP option 121, also in FortiClient. #CVE2024

    Post summary

    The tweet references CVE-2024-3661, noting it involves a VPN traffic leak via DHCP option 121 in FortiClient, but offers no further technical depth or additional context.

    1000065
    311 followersView on X
  • 瑞輝智佳@遊現怪舎エージーテクソル/代表取り締まられ役舎長@chikamizuki1993
    General

    CVE-2024-3661 にハマった。 理屈は分かるが、悪用のハードルは高い気がする。 要は Free Wi-Fi とかホテル、ネカフェなんかの信頼出来ないネットワークを使うんじゃねぇ!😡と…… しかしコレの対応をされているとVPNトンネルの重ねがけみたいなコトが難しくなるな😰 VPNトンネルを張ってる間はルート追加を禁止する対応をしている製品がある……

    Post summary

    The post notes the CVE‑2024‑3661 vulnerability, suggests it is hard to exploit, warns against using untrusted networks, and references a mitigation that blocks routing during a VPN tunnel, but provides no PoC, exploit, or detailed technical info.

    00000144
    114 followersView on X
CPE platform detail24 entries

24 of 24 entries

PartVendorProductVersionTarget SWTarget HW
OSappleiphone_os---
OSapplemacos---
Appciscoanyconnect_vpn_client---
Appciscosecure_client---
Appcitrixsecure_access_client---
Appf5big-ip_access_policy_manager---
Appfortinetforticlient-linux-
Appfortinetforticlient-macos-
Appfortinetforticlient-windows-
Appfortinetforticlient7.4.0linux-
Appfortinetforticlient7.4.0macos-
Appfortinetforticlient7.4.0windows-
OSlinuxlinux_kernel---
Apppaloaltonetworksglobalprotect-iphone_os-
Apppaloaltonetworksglobalprotect-linux-
Apppaloaltonetworksglobalprotect-macos-
Apppaloaltonetworksglobalprotect-windows-
Appwatchguardipsec_mobile_vpn_client-macos-
Appwatchguardipsec_mobile_vpn_client-windows-
Appwatchguardmobile_vpn_with_ssl-macos-
Appwatchguardmobile_vpn_with_ssl-windows-
Appzscalerclient_connector-linux-
Appzscalerclient_connector-macos-
Appzscalerclient_connector-windows-

Explore more