Back to Database
Status published
Medium
CVE-2025-23019
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and...
Vulnerability Description
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23019
Credits & Attribution
No credits recorded in the NVD database.
References
More from IETF
View All →CVE-2025-27371
In certain IETF OAuth 2.0-related specifications, when the JSON Web...
Medium
6.9
CVE-2025-23018
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the...
Medium
5.4
CVE-2024-7596
Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet
Unknown
0
CVE-2024-7595
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet
Unknown
0
CVE-2024-3661
DHCP routing options can manipulate interface-based VPN traffic
High
7.6
Affected Vendor
IETF
View all reports →Affected Software
IPv6
Vulnerable Versions:
6
Timeline
Official Publish:
January 14th, 2025
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.