CVE-2023-36325
LOWi2p < 2.3.0 - Observable Discrepancy via Replayed Tunneled Message
Title source: llmDescription
i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior discrepancy (it may be dropped, or may result in a Wrong Destination response). An attack would take days to complete.
References (3)
Core 3
Core References
Various Sources
https://xeiaso.net/blog/CVE-2023-36325
Various Sources
https://geti2p.net/en/blog/post/2023/06/25/new_release_2.3.0
Scores
CVSS v3
3.7
EPSS
0.0039
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-203
Status
published
Published
Oct 09, 2024
Tracked Since
Feb 18, 2026