A vulnerability that allows intercepting TCP connections established through VPN tunnels.
An attack technique (CVE-2019-14899) has been published, allowing packets in TCP connections passed through VPN tunnels to be spoofed, altered, or substituted. The issue affects Linux, FreeBSD, OpenBSD, Android, macOS, iOS, and other Unix-like systems. Linux supports the rp_filter (reverse path filtering) mechanism for IPv4, the activation of which in 'Strict' mode neutralizes this issue. This method allows packet substitution at the TCP connection level, occurring within encrypted […]
