An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that traffic to the local network is sent in plaintext outside the VPN tunnel even if the local network is using a non-RFC1918 IP subnet. This allows an adversary to trick the victim into sending arbitrary IP traffic in plaintext outside the VPN tunnel. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in leakage of traffic in plaintext" rather than to only Clario.
Conclusion & alert: CVE-2023-36672 is rated Exploit Available (55.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.68%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.03% | 0.68% | +0.65% |
| 2 | 2025-11-21 | 0.05% | 0.03% | -0.02% |
| 3 | 2025-11-18 | — | 0.05% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.7 | 3.1 | MEDIUM |
|
2.1 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2023-36672 medium priority: Ubuntu including 31 source packages (connman, gadmin-openvpn-client, …), 341 status rows across 11 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, trusty, upstream, xenial): not-affected 206, DNE 82, ignored 53. | https://ubuntu.com/security/CVE-2023-36672 |
| URL | Tags |
|---|---|
| https://clario.co/vpn-for-mac/ | Product |
| https://mullvad.net/de/blog/2023/8/9/response-to-tunnelcrack-vulnerability-disclosure/ | Third Party Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0015 | |
| https://tunnelcrack.mathyvanhoef.com/details.html | Exploit Third Party Advisory |