CVE-2020-25705
Last modified
CVE-2020-25705 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. EPSS estimates a 6.69% chance of exploitation in the next 30 days.
Description
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: Version
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.10.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25705?
How severe is CVE-2020-25705?
How do I fix CVE-2020-25705?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-2570Vulnerability in the MySQL Client product of Oracle MySQL (c…5.9
- CVE-2020-25700In moodle, some database module web services allowed student…6.5
- CVE-2020-25701If the upload course tool in Moodle was used to delete an en…5.3
- CVE-2020-25702In Moodle, it was possible to include JavaScript when re-nam…6.1
- CVE-2020-25703The participants table download in Moodle always included us…5.3
- CVE-2020-25704A flaw memory leak in the Linux kernel performance monitorin…5.5
- CVE-2020-25706A cross-site scripting (XSS) vulnerability exists in templat…6.1
- CVE-2020-25707Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2020-25708A divide by zero issue was found to occur in libvncserver-0.…7.5
- CVE-2020-25709A flaw was found in OpenLDAP. This flaw allows an attacker w…7.5
- CVE-2020-2571Vulnerability in the Oracle VM Server for SPARC product of O…3.3
- CVE-2020-25710A flaw was found in OpenLDAP in versions before 2.4.56. This…7.5
Are you affected by CVE-2020-25705?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
