CVE-2020-10749

Aliases:GHSA-fx6x-h9g4-56f8GO-2023-1915RHSA-2020:2403RHSA-2020:2443RHSA-2020:2592RHSA-2020:2684DEBIAN-CVE-2020-10749CGA-22v6-f6h2-6wq9CGA-36wx-75fc-f862CGA-37rf-8cr9-pcc8CGA-3g6g-5v9c-93q2CGA-43q8-26rh-vp26CGA-4cww-9c3j-c4h3CGA-4g58-jcpj-p5j8CGA-5285-h78f-3wwcCGA-577m-fw8g-4792CGA-5f83-2cw5-j7fgCGA-5rjf-cpqv-x4g8CGA-5xgf-9q9f-j2vgCGA-635q-38wp-844hCGA-6995-h3x3-8gh5CGA-6gc2-682v-8cp9CGA-6m9c-49mg-mmf4CGA-6vwc-248c-fqhxCGA-79m5-c4w2-53pvCGA-7jhh-j3vv-fh74CGA-7rqp-f83v-cq47CGA-869q-38h5-r32mCGA-879w-3jmv-gxxhCGA-87fh-6w84-gcxpCGA-8fx7-r9rv-ggffCGA-8vcj-4pp6-r3wqCGA-9gw6-q3xh-79v4CGA-9whj-p6hx-wwp5CGA-c3mm-vpvh-c48rCGA-crg2-6wx4-ffr7CGA-ffcq-jj3j-w7gpCGA-fm85-74c7-fh92CGA-g3pr-vghg-v3v5CGA-g76f-c3xc-p3f7CGA-gj6h-6r7h-h7qcCGA-gvc4-xqxf-9459CGA-gvvv-6rm6-v3x3CGA-gwhw-cxw3-44wjCGA-h52m-2c42-m8q8CGA-hf9f-9qh3-225mCGA-hpwq-q853-j2q2CGA-hw4v-37vh-67wfCGA-hwj6-mm6m-v58gCGA-j42q-f8j3-x4fwCGA-j9w6-qh5c-xjrcCGA-jg44-w6hv-9gc5CGA-jgv9-4m7x-2c3fCGA-jq9x-wpwq-2gfxCGA-jvv4-c875-4469CGA-m2wx-c38j-mqcpCGA-m2x6-gh9q-x36wCGA-mqxh-qmmm-ppqpCGA-mr94-2pcf-x95fCGA-p4f6-mmwm-mmqqCGA-p5w6-8266-gxxvCGA-pg4x-9p6m-cm99CGA-ph87-25vm-w2q3CGA-phrh-qjpj-gqvhCGA-q5p5-3894-7j6cCGA-qgvx-w8g5-fw78CGA-qxqc-8f6w-ghwvCGA-r4p8-7ggp-xqg5CGA-rhr3-f8p8-w437CGA-rr2x-r9fq-63h2CGA-rvjc-63w7-r63mCGA-v6r9-phhg-23g8CGA-v7vm-pwf4-phc9CGA-vv9w-cxvw-cc84CGA-wf2x-3g48-4g47CGA-x2hh-h9xf-wxqfCGA-x52f-f8w9-4fh9CGA-xg9v-82j7-gpf9CGA-xgwc-c783-m8wc
Modified
Published: 03 Jun 2020, 13:45
Last modified:04 Aug 2024, 11:14

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
6 MEDIUM
v3.1 (cve.org)
EPSS Score
2.43% LOW
2% probability -2.76%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jun 2020, 13:45
Published
Vulnerability first disclosed
04 Aug 2024, 11:14
Last Modified
Vulnerability information updated

Description

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS Metrics

  • v3.1MEDIUMScore: 6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
  • v2.0MEDIUMScore: 6AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 2.43% Percentile: 83%

Techniques & Countermeasures

  • CWE-300Channel Accessible by Non-Endpoint

    The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.

Affected Systems

  • chainguardcni-plugins-fips

    < 0

  • chainguardcni-plugins-fips-bandwidth

    < 0

  • chainguardcni-plugins-fips-bandwidth-compat

    < 0

  • chainguardcni-plugins-fips-bridge

    < 0

  • chainguardcni-plugins-fips-bridge-compat

    < 0

  • chainguardcni-plugins-fips-dhcp

    < 0

  • chainguardcni-plugins-fips-dhcp-compat

    < 0

  • chainguardcni-plugins-fips-dummy

    < 0

  • chainguardcni-plugins-fips-dummy-compat

    < 0

  • chainguardcni-plugins-fips-firewall

    < 0

  • chainguardcni-plugins-fips-firewall-compat

    < 0

  • chainguardcni-plugins-fips-host-device

    < 0

  • chainguardcni-plugins-fips-host-device-compat

    < 0

  • chainguardcni-plugins-fips-host-local

    < 0

  • chainguardcni-plugins-fips-host-local-compat

    < 0

  • chainguardcni-plugins-fips-ipam

    < 0

  • chainguardcni-plugins-fips-ipvlan

    < 0

  • chainguardcni-plugins-fips-ipvlan-compat

    < 0

  • chainguardcni-plugins-fips-loopback

    < 0

  • chainguardcni-plugins-fips-loopback-compat

    < 0

  • chainguardcni-plugins-fips-macvlan

    < 0

  • chainguardcni-plugins-fips-macvlan-compat

    < 0

  • chainguardcni-plugins-fips-main

    < 0

  • chainguardcni-plugins-fips-meta

    < 0

  • chainguardcni-plugins-fips-portmap

    < 0

  • chainguardcni-plugins-fips-portmap-compat

    < 0

  • chainguardcni-plugins-fips-ptp

    < 0

  • chainguardcni-plugins-fips-ptp-compat

    < 0

  • chainguardcni-plugins-fips-sbr

    < 0

  • chainguardcni-plugins-fips-sbr-compat

    < 0

  • chainguardcni-plugins-fips-static

    < 0

  • chainguardcni-plugins-fips-static-compat

    < 0

  • chainguardcni-plugins-fips-tuning

    < 0

  • chainguardcni-plugins-fips-tuning-compat

    < 0

  • chainguardcni-plugins-fips-vlan

    < 0

  • chainguardcni-plugins-fips-vlan-compat

    < 0

  • debiangolang-github-containernetworking-plugins

    < 0.8.6-1 | < 0.8.6-1 | < 0.8.6-1 | < 0.8.6-1

  • fedoraprojectfedora

    32

  • github.com/containernetworkingplugins

    < 0.8.6

  • linuxfoundationcni_network_plugins

    < 0.8.6

  • red hatcontainernetworking/plugins

    all containernetworking/plugins versions before version 0.8.6

  • redhatenterprise_linux

    7.0 | 8.0

  • redhatopenshift_container_platform

    4.0

  • redhatcontainernetworking-plugins

    < 0:0.8.6-1.rhaos4.4.el7 | < 0:0.8.6-1.rhaos4.4.el8 | < 0:0.8.6-1.rhaos4.3.el7 | < 0:0.8.6-1.rhaos4.3.el8 | < 0:0.8.6-1.rhaos4.2.el7 | < 0:0.8.6-1.rhaos4.2.el8 | < 0:0.8.3-3.el7_8

  • redhatcontainernetworking-plugins-debuginfo

    < 0:0.8.6-1.rhaos4.4.el7 | < 0:0.8.6-1.rhaos4.4.el8 | < 0:0.8.6-1.rhaos4.3.el7 | < 0:0.8.6-1.rhaos4.3.el8 | < 0:0.8.6-1.rhaos4.2.el7 | < 0:0.8.6-1.rhaos4.2.el8 | < 0:0.8.3-3.el7_8

  • redhatcontainernetworking-plugins-debugsource

    < 0:0.8.6-1.rhaos4.4.el8 | < 0:0.8.6-1.rhaos4.3.el8 | < 0:0.8.6-1.rhaos4.2.el8

References (24)