CVE-2020-14305 describes an out-of-bounds memory write vulnerability in the Linux kernel's H.323 connection tracking functionality, specifically impacting IPv6 port 1720, and also affecting NetApp products. This flaw carries a high severity CVSS score of 8.1, indicating that an unauthenticated remote attacker can exploit it with high attack complexity to cause a denial of service, and potentially impact confidentiality and integrity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a Threatpost article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.11.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.12:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:fas_500f_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.