CVE-2020-25660 is a high-severity flaw in the Cephx authentication protocol affecting Ceph versions before 15.2.6 and 14.2.14, as well as various Red Hat and Fedora products. It allows an attacker on the Ceph cluster network to bypass authentication via replay attacks, leading to potential compromise of confidentiality, integrity, and availability. With a CVSS score of 8.8 (High), this vulnerability requires network access but no user interaction or privileges. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.2.14CPE matchmatch criteria | cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.2.6CPE matchmatch criteria | cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.