State Issues in FreeBSD - CVE-2024-6640
Published: August 8, 2024
Vulnerability identifier: #VU95542
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-6640
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass pf rules.
The vulnerability exists due to improper handling of ICMPv6 packets with ID=0. If the firewall is configured to block incoming Echo requests, this rule can be bypass by sending an ICMPv6 packet with identifier value of zero.
Affected software
FreeBSD
How to mitigate CVE-2024-6640
Install updates from vendor's website.