CVE-2020-10136
Last modified
CVE-2020-10136 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.. EPSS estimates a 26.46% chance of exploitation in the next 30 days.
Description
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 5.2\(1\)sk3\(1.1\) |
| Cisco | Nx-Os | 5.2\(1\)sk3\(2.1\) |
| Cisco | Nx-Os | 5.2\(1\)sk3\(2.1a\) |
| Cisco | Nx-Os | 5.2\(1\)sk3\(2.2\) |
| Cisco | Nx-Os | 5.2\(1\)sk3\(2.2b\) |
| Cisco | Nx-Os | 5.2\(1\)sm1\(5.1\) |
| Cisco | Nx-Os | 5.2\(1\)sm1\(5.2\) |
| Cisco | Nx-Os | 5.2\(1\)sm1\(5.2a\) |
| Cisco | Nx-Os | 5.2\(1\)sm1\(5.2b\) |
| Cisco | Nx-Os | 5.2\(1\)sm1\(5.2c\) |
| Cisco | Nx-Os | 5.2\(1\)sm3\(1.1\) |
| Cisco | Nx-Os | 5.2\(1\)sm3\(1.1a\) |
| Cisco | Nx-Os | 5.2\(1\)sm3\(1.1b\) |
| Cisco | Nx-Os | 5.2\(1\)sm3\(1.1c\) |
| Cisco | Nx-Os | 5.2\(1\)sm3\(2.1\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.1\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.2\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.3\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.4\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.4b\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.5a\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.5b\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.6\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.10\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(1.15\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(2.1\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(2.5\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(2.8\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(3.1\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(3.15\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(4.1\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(4.1a\) |
| Cisco | Nx-Os | 5.2\(1\)sv3\(4.1b\) |
| Cisco | Nx-Os | 5.2\(1\)sv5\(1.1\) |
| Cisco | Nx-Os | 5.2\(1\)sv5\(1.2\) |
| Cisco | Nx-Os | 5.2\(1\)sv5\(1.3\) |
| Cisco | Nx-Os | 5.0\(3\)a1\(1\) |
| Cisco | Nx-Os | 5.0\(3\)a1\(2\) |
| Cisco | Nx-Os | 5.0\(3\)a1\(2a\) |
| Cisco | Nx-Os | 5.0\(3\)u1\(1\) |
| Cisco | Nx-Os | 5.0\(3\)u1\(1a\) |
| Cisco | Nx-Os | 5.0\(3\)u1\(1b\) |
| Cisco | Nx-Os | 5.0\(3\)u1\(1c\) |
| Cisco | Nx-Os | 5.0\(3\)u1\(1d\) |
| Cisco | Nx-Os | 5.0\(3\)u1\(2\) |
| Cisco | Nx-Os | 5.0\(3\)u1\(2a\) |
| Cisco | Nx-Os | 5.0\(3\)u2\(1\) |
| Cisco | Nx-Os | 5.0\(3\)u2\(2\) |
| Cisco | Nx-Os | 5.0\(3\)u2\(2a\) |
| Cisco | Nx-Os | 5.0\(3\)u2\(2b\) |
Showing 50 of 258 affected configurations. See NVD for the full list.
References
- https://kb.cert.org/vuls/id/636397/Third Party Advisory, US Government Resource
- https://www.digi.com/resources/securityThird Party Advisory
- https://www.kb.cert.org/vuls/id/636397Third Party Advisory, US Government Resource
- https://kb.cert.org/vuls/id/636397/Third Party Advisory, US Government Resource
- https://www.digi.com/resources/securityThird Party Advisory
- https://www.kb.cert.org/vuls/id/636397Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10136?
How severe is CVE-2020-10136?
How do I fix CVE-2020-10136?
Are you affected by CVE-2020-10136?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
