{"id":"CVE-2023-35838","details":"The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to \"LocalNet attack resulting in the blocking of traffic\" rather than to only WireGuard.","aliases":["PYSEC-2023-321"],"modified":"2026-08-12T03:51:25.003857678Z","published":"2023-08-09T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35838.json"},"references":[{"type":"WEB","url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0015"},{"type":"WEB","url":"https://tunnelcrack.mathyvanhoef.com/details.html"},{"type":"WEB","url":"https://wireguard.com"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35838.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-35838"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wireguard/wireguard-windows","events":[{"introduced":"28e903804aa1302b791c24093dd7f42f0c7d0952"},{"last_affected":"28e903804aa1302b791c24093dd7f42f0c7d0952"}],"database_specific":{"cpe":"cpe:2.3:a:wireguard:wireguard:0.5.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.5.3"},{"last_affected":"0.5.3"}],"source":"CPE_STRING"}}],"versions":["0.5.3","v0.5.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-35838.json"}}],"schema_version":"1.9.0"}