> Source: [sk182290](https://support.checkpoint.com/results/sk/sk182290)

# sk182290 - Check Point response to CVE-2024-3661 (TunnelVision Vulnerability)

| Property | Value |
|----------|-------|
| Solution ID | sk182290 |
| Date Created | 2024-05-15 |
| Last Modified | 2024-12-23 |
| Technical Level | General |
| Products | Security Gateway, Endpoint Security |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS), E89.X, E88.X |

## Solution

We assessed the impact of the recent TunnelVision attack ([CVE-2024-3661](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3661)) and determined that Check Point Quantum VPN is impervious to this threat.  

These client types do not have support for DHCP option 121:  

* SecuRemote
* SSL Network Extender
* Capsule Connect
* Capsule VPN
* Endpoint Security VPN
* Endpoint Security Client
* Mobile Access / SSL VPN
* Capsule Workspace
* SecureClient Mobile
* SecureClient
* strongSwan

However, we offer support for DHCP option 121 exclusively for L2TP clients. When connecting with L2TP and utilizing DHCP option 121, the DHCP server's response undergoes filtration, with the static routes of option 121 being substituted by the routes configured within the Check Point VPN Security Gateway's encryption domain, functioning similarly to other client types.  

In summary, all VPN clients are protected from such attacks.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
