An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel, even if this traffic is not generated by the VPN client, while simultaneously using plaintext DNS to look up the VPN server's IP address. This allows an adversary to trick the victim into sending traffic to arbitrary IP addresses in plaintext outside the VPN tunnel. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "ServerIP attack, combined with DNS spoofing, that can leak traffic to an arbitrary IP address" rather than to only Avira Phantom VPN.
Conclusion & alert: CVE-2023-36673 is rated Exploit Available (50/100): CVSS High severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.06% | 0.04% | -0.02% |
| 2 | 2025-11-18 | 0.04% | 0.06% | +0.02% |
| 3 | 2025-04-15 | — | 0.04% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
2.1 | 5.2 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2023-36673 medium priority: Ubuntu including 31 source packages (connman, gadmin-openvpn-client, …), 341 status rows across 11 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, trusty, upstream, xenial): not-affected 211, DNE 82, ignored 48. | https://ubuntu.com/security/CVE-2023-36673 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| avira | phantom_vpn | <= 2.23.1 | cpe:2.3:a:avira:phantom_vpn:*:*:*:*:*:macos:*:* |
| URL | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0015 | |
| https://tunnelcrack.mathyvanhoef.com/details.html | Exploit Third Party Advisory |
| https://www.avira.com/en/free-vpn | Product |