Sploitus

CVE-2020-10136

No indexed exploits for CVE-2020-10136 yet

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

Affected products
Cisco Nx-Os, Cisco Nexus
Cisco Nx-os
= 5.2\(1\)sk3\(1.1\), 5.2\(1\)sk3\(2.1\), 5.2\(1\)sk3\(2.1a\), 5.2\(1\)sk3\(2.2\), 5.2\(1\)sk3\(2.2b\), 5.2\(1\)sm1\(5.1\), 5.2\(1\)sm1\(5.2\), 5.2\(1\)sm1\(5.2a\), 5.2\(1\)sm1\(5.2b\), 5.2\(1\)sm1\(5.2c\), 5.2\(1\)sm3\(1.1\), 5.2\(1\)sm3\(1.1a\), 5.2\(1\)sm3\(1.1b\), 5.2\(1\)sm3\(1.1c\), 5.2\(1\)sm3\(2.1\), 5.2\(1\)sv3\(1.1\), 5.2\(1\)sv3\(1.2\), 5.2\(1\)sv3\(1.3\), 5.2\(1\)sv3\(1.4\), 5.2\(1\)sv3\(1.4b\), 5.2\(1\)sv3\(1.5a\), 5.2\(1\)sv3\(1.5b\), 5.2\(1\)sv3\(1.6\), 5.2\(1\)sv3\(1.10\), 5.2\(1\)sv3\(1.15\), 5.2\(1\)sv3\(2.1\), 5.2\(1\)sv3\(2.5\), 5.2\(1\)sv3\(2.8\), 5.2\(1\)sv3\(3.1\), 5.2\(1\)sv3\(3.15\), 5.2\(1\)sv3\(4.1\), 5.2\(1\)sv3\(4.1a\), 5.2\(1\)sv3\(4.1b\), 5.2\(1\)sv5\(1.1\), 5.2\(1\)sv5\(1.2\), 5.2\(1\)sv5\(1.3\)
CVSS 3.1
5.3 MEDIUM
EPSS
28.5% (98th percentile)
Weakness
CWE-290
NVD status
Modified
Published
2020-06-02

Fix

Customers should apply the latest patch provided by the affected vendor that addresses this issue and prevents unspecified IP-in-IP packets from being processed. Devices manufacturers are urged to disable IP-in-IP in their default configuration and require their customers to explicitly configure IP-in-IP as and when needed.

Workaround

Users can block IP-in-IP packets by filtering IP protocol number 4. Note this filtering is for the IPv4 Protocol (or IPv6 Next Header) field value of 4 and not IP protocol version 4 (IPv4).

CVE-2020-10136 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-10136 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-10136 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.