ZeroHour

CVE-2023-48957

PoC ×2
CVSS 3.1
5.3 medium
EPSS
<1%p37
Published
()
Modified
Description

PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers.

Vendors
purevpn
Products
purevpn
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.