State Issues in FreeBSD - CVE-2024-6640

 

State Issues in FreeBSD - CVE-2024-6640

Published: August 8, 2024


Vulnerability identifier: #VU95542
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-6640
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass pf rules.

The vulnerability exists due to improper handling of ICMPv6 packets with ID=0. If the firewall is configured to block incoming Echo requests, this rule can be bypass by sending an ICMPv6 packet with identifier value of zero.


Affected software

FreeBSD

How to mitigate CVE-2024-6640

Install updates from vendor's website.


External References

Related Security Bulletins