Executive Summary



This vulnerability is currently undergoing analysis and not all information is available. Please check back soon to view the completed vulnerability summary
Informations
Name CVE-2025-24356 First vendor Publication 2025-01-27
Vendor Cve Last vendor Modification 2025-01-27

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address and initiate a reconnect by sending a handshake packet. This "fast reconnect" avoids having to wait for a session timeout (up to ~90s) until a new connection is established. Even a 1-byte UDP packet just containing the fastd packet type header can trigger a much larger handshake packet (~150 bytes of UDP payload). Including IPv4 and UDP headers, the resulting amplification factor is roughly 12-13. By sending data packets with a spoofed source address to fastd instances reachable on the internet, this amplification of UDP traffic might be used to facilitate a Distributed Denial of Service attack. This vulnerability is fixed in v23.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24356

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-405 Asymmetric Resource Consumption (Amplification)

Sources (Detail)

https://github.com/neocturne/fastd/commit/1f233bee76b722c0b3f9024f2c39c72e9f7...
https://github.com/neocturne/fastd/commit/3940150e801d0c91460491bec32cbcc5bbc...
https://github.com/neocturne/fastd/commit/5f63fcfc18ae9cad023fa463b152d5e1419...
https://github.com/neocturne/fastd/commit/9df7e516378441d2d17b89f9db5c27c8312...
https://github.com/neocturne/fastd/commit/c1a07b3f2b9066c3713c68547da700b85d6...
https://github.com/neocturne/fastd/commit/ce1b79b12dbfa796743b5f3a50789ade965...
https://github.com/neocturne/fastd/commit/d03a0a17347efb5293e42fde7d982781e90...
https://github.com/neocturne/fastd/security/advisories/GHSA-pggg-vpfv-4rcv
Source Url

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2025-01-27 21:20:30
  • First insertion