CVE-2023-48957

MEDIUM

PureVPN Linux client <2.0.2-Productions - Info Disclosure

Title source: llm
STIX 2.1

Description

PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers.

Scores

CVSS v3 5.3
EPSS 0.0044
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
purevpn/purevpn 2.0.2
Published Aug 25, 2024
Tracked Since Feb 18, 2026