CVE-2020-14305

Modified
Published: 02 Dec 2020, 00:48
Last modified:04 Aug 2024, 12:39

Vulnerability Summary

Overall Risk (default)
medium
44/100
CVSS Score
8.3 HIGH
v2.0 (nvd)
EPSS Score
4.41% LOW
4% probability +3.36%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

02 Dec 2020, 00:48
Published
Vulnerability first disclosed
04 Aug 2024, 12:39
Last Modified
Vulnerability information updated

Description

An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 8.3AV:N/AC:M/Au:N/C:P/I:P/A:C

EPSS Trends

Current EPSS score: 4.41% Percentile: 89%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • linuxlinux_kernel

    ≤ 4.11.12 | 4.1.2

  • netappa250_firmware

    na

  • netappaff_500f_firmware

    na

  • netappcloud_backup

    na

  • netappfas_500f_firmware

    na

  • netappsolidfire_baseboard_management_controller_firmware

    na

References (4)