CVE-2020-10136 is a medium-severity vulnerability affecting the IP-in-IP protocol implementation in products from vendors like Cisco, Digi, HP, and Treck. It stems from a lack of validation before decapsulating and routing IP-in-IP traffic, leading to potential spoofing, access-control bypass, and other unexpected behaviors. The vulnerability has a CVSS score of 5.3 (MEDIUM) and an EPSS score indicating it is more likely to be exploited than 94.5% of all CVEs. The attack vector is network-based with low attack complexity, requiring no user interaction or privileges. While the impact is limited to availability (A:L), the FAUCET Risk Score of 90/100 suggests a significant concern. Currently, there is no evidence of active exploitation (KEV: No), and no public exploit code is available on platforms like Metasploit or ExploitDB. However, the vulnerability has garnered some community attention with mentions on Reddit and media coverage from SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2\(1\)sk3\(1.1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:5.2\(1\)sk3\(1.1\):*:*:*:*:*:*:* | ||
5.2\(1\)sk3\(2.1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:5.2\(1\)sk3\(2.1\):*:*:*:*:*:*:* | ||
5.2\(1\)sk3\(2.1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:5.2\(1\)sk3\(2.1a\):*:*:*:*:*:*:* | ||
5.2\(1\)sk3\(2.2\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:5.2\(1\)sk3\(2.2\):*:*:*:*:*:*:* | ||
5.2\(1\)sk3\(2.2b\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:5.2\(1\)sk3\(2.2b\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.