Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8554

24
FAUCET Score

CVE-2020-8554 is a medium-severity vulnerability affecting all versions of Kubernetes, allowing an attacker to intercept traffic by manipulating ClusterIP or LoadBalancer service configurations. This man-in-the-middle attack requires specific privileges, such as the ability to create services with externalIPs or patch LoadBalancer service statuses. The vulnerability has a CVSS score of 5.0 (Medium) due to its network attack vector and high attack complexity, potentially leading to limited impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion and media coverage, indicating awareness and concern within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
1.2.1CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:*
1.15.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
1.14.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
9.27%
Probability of exploitation in next 30 days
EPSS Percentile
94.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0927 is in the 97th percentile among its peer group of 1,424 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

denopatch availablevia llm_extracted
Fixed in: 1.21
View patch
invoiceplanepatch availablevia llm_extracted
Fixed in: 1.21
View patch
microsoftpatch availablevia msrc
Product: 19103-17084Fixed in: 1.28.3-2
microsoftpatch availablevia msrc
Product: 19099-16820Fixed in: 1.22.4-2
microsoftpatch availablevia msrc
Product: 19100-16823Fixed in: 1.28.3-1
microsoftpatch availablevia msrc
Product: 19101-16823Fixed in: 21.7.0-1
microsoftpatch availablevia msrc
Product: 19102-17084Fixed in: 21.7.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 1.28.3-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 1.28.3-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.28.3-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.28.3-1
microsoftpatch availablevia msrc
Product: azl3 python-kubernetes 21.7.0-1 on Azure Linux 3.0Fixed in: 21.7.0-1
microsoftpatch availablevia msrc
Product: cbl2 python-kubernetes 21.7.0-1 on CBL Mariner 2.0Fixed in: 21.7.0-1
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.30.10-7 on Azure Linux 3.0Fixed in: 1.28.3-2
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.28.3-2 on Azure Linux 3.0Fixed in: 1.28.3-2
microsoftpatch availablevia msrc
Product: cbl2 kubernetes 1.28.3-1 on CBL Mariner 2.0Fixed in: 1.28.3-1
microsoftpatch availablevia msrc
Product: cm1 kubernetes 1.22.4-2 on CBL Mariner 1.0Fixed in: 1.22.4-2
microsoftpatch availablevia msrc
Product: 19340-17084Fixed in: 1.28.3-2
oraclepatch availablevia nvd_reference
View patch
pjsippatch availablevia llm_extracted
Fixed in: 1.21
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.374-1.git.0.ebd3ee9.el7
View patch
check_pointvendor investigatingvia llm_extracted
View patch
chromevendor investigatingvia llm_extracted
View patch
infiniflowvendor investigatingvia llm_extracted
View patch
vuevendor investigatingvia llm_extracted
View patch

Vendor Advisories (11)

microsoft2024-Jun/CVE-2020-8554

CVE-2020-8554

Jun 11, 2024
goGHSA-j9wf-vvm6-4r9wmedium

Unverified Ownership in Kubernetes

Feb 8, 2022
invoiceplanellm-invoiceplane-133dcbd2cff5d34bMEDIUM

The Kubernetes project recently discovered a new security vulnerability, CVE-2020-8554, that might allow an attacker who has obtained permissions to create a Kubernetes Service of type LoadBalancer or ClusterIP to intercept network traffic originating from other Pods in the cluster.

Dec 22, 2021
denollm-deno-05d2820381717f67MEDIUM

Kubernetes Service Traffic Interception Vulnerability

Dec 22, 2021
microsoft2021-Jan/CVE-2020-8554Moderate

Kubernetes man in the middle using LoadBalancer or ExternalIPs

Jan 12, 2021
redhatCVE-2020-8554Moderate

kubernetes: MITM using LoadBalancer or ExternalIPs

Dec 7, 2020
pjsipllm-pjsip-26ffcc907d812b29MEDIUM

Kubernetes Service ExternalIPs Traffic Interception

Jan 1, 2020
check_pointllm-check_point-aae23c1d193ce70b

Man in the middle using LoadBalancer or ExternalIPs

chromellm-chrome-ba5c93841850050d

Man in the middle using LoadBalancer or ExternalIPs

infiniflowllm-infiniflow-6f849e6c1a60f5fd

Man in the middle using LoadBalancer or ExternalIPs

vuellm-vue-37a7fb56d231964f

Man in the middle using LoadBalancer or ExternalIPs

References

github.com / kubernetes/kubernetes/issues/97076
ExploitThird Party Advisory
groups.google.com / g/kubernetes-security-announce/c/iZWsF9nbKE8
Mailing ListThird Party Advisory
kubernetes.io / blog/2026/05/26/reconciling-unfixed-kubernetes-cves
lists.apache.org / thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40%40%3Ccommits.druid.apache.org%3E
lists.apache.org / thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942%40%3Ccommits.druid.apache.org%3E
lists.apache.org / thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3%40%3Ccommits.druid.apache.org%3E
lists.apache.org / thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6%40%3Ccommits.druid.apache.org%3E
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory