V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-10136
CVE
High

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable…

CVSS
7.5
High
EPSS
0.26
p97
Published
2020-01-01
Updated
2020-01-01
Description

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

Tags · CWE
Pre-auth
CWE-284
CWE-290
CAPEC-19
CAPEC-21
CAPEC-22
CAPEC-59
CAPEC-60
CAPEC-94
CAPEC-441
CAPEC-459
CAPEC-461
CAPEC-473
CAPEC-476
CAPEC-478
CAPEC-479
CAPEC-502
CAPEC-503
CAPEC-536
CAPEC-546
CAPEC-550
CAPEC-551
CAPEC-552
CAPEC-556
CAPEC-558
CAPEC-562
CAPEC-563
CAPEC-564
CAPEC-578
CAPEC-667
Affected products
Saros < 8.1.0.1
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.265 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-552 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-473 · CWE-290
└ via CAPEC-564 · CWE-284
└ via CAPEC-562 · CWE-284
└ via CAPEC-21 · CWE-290
└ via CAPEC-60 · CWE-290
└ via CAPEC-558 · CWE-284
└ via CAPEC-21 · CWE-290
└ via CAPEC-21 · CWE-290
└ via CAPEC-552 · CWE-284
└ via CAPEC-550 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-478 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-556 · CWE-284
└ via CAPEC-558 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-552 · CWE-284
└ via CAPEC-60 · CWE-290
└ via CAPEC-473 · CWE-290
└ via CAPEC-479 · CWE-284
└ via CAPEC-578 · CWE-284
└ via CAPEC-94 · CWE-290
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
nx-os*Tracked
nx-os*Tracked
nx-os*Tracked
nx-os*Tracked
nx-os*Tracked
saros*Tracked
tcp/ip*Tracked
ucs_manager*Tracked
unified_computing_system*Tracked
x3220nr_firmware*Tracked
Source databases
CVE
Related vulnerabilities