#VU95542 State Issues in FreeBSD - CVE-2024-6640

 

#VU95542 State Issues in FreeBSD - CVE-2024-6640

Published: August 8, 2024


Vulnerability identifier: #VU95542
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-6640
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
FreeBSD
Software vendor:
FreeBSD Foundation

Description

The vulnerability allows a remote attacker to bypass pf rules.

The vulnerability exists due to improper handling of ICMPv6 packets with ID=0. If the firewall is configured to block incoming Echo requests, this rule can be bypass by sending an ICMPv6 packet with identifier value of zero.


Remediation

Install updates from vendor's website.

External links