7.5
CVE-2020-25645
- EPSS 2.43%
- Veröffentlicht 13.10.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:19
- Erkennungen
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 5.9.0
Linux ≫ Linux Kernel Version 5.9.0 Update -
Linux ≫ Linux Kernel Version 5.9.0 Update rc1
Linux ≫ Linux Kernel Version 5.9.0 Update rc2
Linux ≫ Linux Kernel Version 5.9.0 Update rc3
Linux ≫ Linux Kernel Version 5.9.0 Update rc4
Linux ≫ Linux Kernel Version 5.9.0 Update rc5
Linux ≫ Linux Kernel Version 5.9.0 Update rc6
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Netapp ≫ Solidfire & Hci Management Node Version -
Netapp ≫ Solidfire & Hci Storage Node Version -
Netapp ≫ Hci Compute Node Bios Version -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.43% | 0.823 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
https://lists.debian.org/debian-lts-announce/2020/10/msg00028.html
https://www.debian.org/security/2020/dsa-4774
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00035.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html
http://packetstormsecurity.com/files/161229/Kernel-Live-Patch-Security-Notice-LSN-0074-1.html
https://lists.debian.org/debian-lts-announce/2020/12/msg00027.html
https://bugzilla.redhat.com/show_bug.cgi?id=1883988
https://security.netapp.com/advisory/ntap-20201103-0004/