CVE-2020-25645

HIGHCVSS 7.5/10EPSS 2.40%

Last modified

CVE-2020-25645 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. EPSS estimates a 2.40% chance of exploitation in the next 30 days.

Description

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
2.40%

81.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LinuxLinux Kernel< 5.9.0
LinuxLinux Kernel5.9.0
DebianDebian Linux9.0
DebianDebian Linux10.0
NetappSolidfire \& Hci Management NodeAll versions
NetappSolidfire \& Hci Storage NodeAll versions
OpensuseLeap15.1
OpensuseLeap15.2
NetappHci Compute Node BiosAll versions
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux20.04

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-25645?
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
How severe is CVE-2020-25645?
CVE-2020-25645 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 2.40% probability of exploitation in the next 30 days.
How do I fix CVE-2020-25645?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-25645?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST