CVE-2025-23019
Published Jan 14, 2025
·Updated
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.
Affected Software
1 affected component
IETF IPv6
Event History
Jan 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Feb 15, 57061
Event
via FIRST·09:09 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-23019?
CVE-2025-23019 is classified as a high severity vulnerability due to its ability to allow traffic spoofing and rerouting.
2
How do I fix CVE-2025-23019?
To mitigate CVE-2025-23019, disable IPv6-in-IPv4 tunneling if it is not expressly needed for your network environment.
3
What systems are affected by CVE-2025-23019?
CVE-2025-23019 affects systems implementing RFC 4213 IPv6-in-IPv4 tunneling.
4
What impact can CVE-2025-23019 have on my network?
CVE-2025-23019 can allow attackers to intercept and manipulate network traffic, leading to data breaches or remote access.
5
Is there any workaround for CVE-2025-23019?
One workaround for CVE-2025-23019 is to implement strict access controls and network segmentation to limit exposure of vulnerable interfaces.