7.5
CVE-2020-25645
- EPSS 0.1%
- Published 13.10.2020 20:15:12
- Last modified 21.11.2024 05:18:19
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Data is provided by the National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 5.9.0
Linux ≫ Linux Kernel Version5.9.0 Update-
Linux ≫ Linux Kernel Version5.9.0 Updaterc1
Linux ≫ Linux Kernel Version5.9.0 Updaterc2
Linux ≫ Linux Kernel Version5.9.0 Updaterc3
Linux ≫ Linux Kernel Version5.9.0 Updaterc4
Linux ≫ Linux Kernel Version5.9.0 Updaterc5
Linux ≫ Linux Kernel Version5.9.0 Updaterc6
Debian ≫ Debian Linux Version9.0
Debian ≫ Debian Linux Version10.0
Netapp ≫ Solidfire & Hci Management Node Version-
Netapp ≫ Solidfire & Hci Storage Node Version-
Netapp ≫ Hci Compute Node Bios Version-
Canonical ≫ Ubuntu Linux Version14.04 SwEditionesm
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version18.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version20.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.276 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.