CVE-2020-15136 describes a medium-severity authentication bypass vulnerability in etcd versions prior to 3.4.10 and 3.3.23, affecting products like Fedora and Red Hat etcd. The flaw allows gateway TLS authentication to be bypassed when endpoints are specified via the --endpoints flag, as authentication is only performed for endpoints discovered through DNS SRV records. This could lead to high confidentiality impact and low integrity impact with a CVSS score of 6.5. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.3.0, < 3.3.23CPE matchmatch criteria | cpe:2.3:a:redhat:etcd:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.10CPE matchmatch criteria | cpe:2.3:a:redhat:etcd:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV records
Jan 31, 2024CVE-2020-15136
Dec 14, 2021Improper authentication in etcd
Aug 11, 2020etcd: no authentication is performed against endpoints provided in the --endpoints flag
Aug 5, 2020