CVE-2020-10136
published 2020-06-02CVE-2020-10136: IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing…
PriorityP342medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
28.54%
97.9th percentile
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
Affected
259 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco8.6HIGH
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jff7-8p33-28j3: Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route
ghsa_unreviewed·2025-02-05·CVSS 5.3
CVE-2024-7596 [MEDIUM] GHSA-jff7-8p33-28j3: Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
GHSA
GHSA-52hm-37gj-qx5h: GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic vi
ghsa_unreviewed·2025-02-05·CVSS 5.3
CVE-2024-7595 [MEDIUM] GHSA-52hm-37gj-qx5h: GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic vi
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
GHSA
GHSA-mf23-wm84-g9x3: IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attack
ghsa_unreviewed·2025-01-14·CVSS 5.3
CVE-2025-23018 [MEDIUM] CWE-940 GHSA-mf23-wm84-g9x3: IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attack
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
GHSA
GHSA-8gxc-83hw-9578: Multiple products that implement the IP Encapsulation within IP standard (RFC 2003, STD 1) decapsulate and route IP-in-IP traffic without any validati
ghsa_unreviewed·2022-05-24
CVE-2020-10136 [MEDIUM] CWE-290 GHSA-8gxc-83hw-9578: Multiple products that implement the IP Encapsulation within IP standard (RFC 2003, STD 1) decapsulate and route IP-in-IP traffic without any validati
Multiple products that implement the IP Encapsulation within IP standard (RFC 2003, STD 1) decapsulate and route IP-in-IP traffic without any validation, which could allow an unauthenticated remote attacker to route arbitrary traffic via an exposed network interface and lead to spoofing, access control bypass, and other unexpected network behaviors.
Red Hat
networkmanager: GRE & GRE6 protocol excessive trust
vendor_redhat·2025-01-14·CVSS 5.3
CVE-2024-7595 [MEDIUM] CWE-348 networkmanager: GRE & GRE6 protocol excessive trust
networkmanager: GRE & GRE6 protocol excessive trust
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
An insecure configuration flaw was found in the GRE and GRE6 Protocols. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Statement: This vulnerability is rated as Low impact as it requires a known higher risk configuration. Multiple layers of defaults (packet forwarding and these specific protocols) are disable
Red Hat
networkmanager: 4in6 and 6in6 protocols excessive trust
vendor_redhat·2025-01-14·CVSS 5.3
CVE-2025-23018 [MEDIUM] CWE-348 networkmanager: 4in6 and 6in6 protocols excessive trust
networkmanager: 4in6 and 6in6 protocols excessive trust
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
An insecure configuration flaw was found in the IPv4-in-IPv6 and IPv6-in-IPv6 protocols (RFC2473). When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Statement: This vulnerability is rated as Low impact as it requires a known higher risk configuration. Multiple layers of defaults (packet forwarding and these specific protocols) are disabled by default. Red Hat p
Red Hat
networkmanager: UDP encapsulation protocol excessive trust
vendor_redhat·2025-01-14·CVSS 5.3
CVE-2024-7596 [MEDIUM] CWE-348 networkmanager: UDP encapsulation protocol excessive trust
networkmanager: UDP encapsulation protocol excessive trust
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
An insecure configuration flaw was found in the Generic UDP Encapsulation Protocol. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Statement: This vulnerability is rated as Low impact as it requires a known higher risk configuration. Multiple layers of defaults (packet forwarding a
Red Hat
kernel: IP-in-IP protocol routes arbitrary traffic by default
vendor_redhat·2020-06-09·CVSS 5.3
CVE-2020-10136 [MEDIUM] CWE-284 kernel: IP-in-IP protocol routes arbitrary traffic by default
kernel: IP-in-IP protocol routes arbitrary traffic by default
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
A flaw was found in the IP-in-IP protocol. An unauthenticated attacker can use the IP-in-IP protocol to route network traffic through a vulnerable device, which can lead to spoofing, access control bypasses, and other unexpected network behaviors.
Statement: The IP-in-IP encapsulation is 'in the clear' tunnel protocol between two hosts. When the module is loaded, the system will be in an 'any-to-any' routing state. It will accept any "I
Cisco
Cisco NX-OS Software Unexpected IP in IP Packet Processing Vulnerability
vendor_cisco·2020-06-01·CVSS 8.6
CVE-2020-10136 [HIGH] CWE-19 Cisco NX-OS Software Unexpected IP in IP Packet Processing Vulnerability
Cisco NX-OS Software Unexpected IP in IP Packet Processing Vulnerability
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass certain security boundaries or cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to the affected device unexpectedly decapsulating and processing IP in IP packets that are destined to a locally configured IP address. An attacker could exploit this vulnerability by sending a crafted IP in IP packet to an affected device. A successful exploit could cause the affected device to unexpectedly decapsulate the IP in IP packet and forward the inner IP packet. This may result in IP packets bypassing input access control lists (ACLs) configured on the affected device or
Cisco
Cisco NX-OS Software Unexpected IP in IP Packet Processing Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-10136 Cisco NX-OS Software Unexpected IP in IP Packet Processing Vulnerability
CVE-2020-10136: Cisco NX-OS Software Unexpected IP in IP Packet Processing Vulnerability
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass certain security boundaries or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the affected device unexpectedly decapsulating and processing IP in IP packets that are destined to a locally configured IP address. An attacker could exploit this vulnerability by sending a crafted IP in IP packet to an affected device. A successful exploit could cause the affected device to unexpectedly decapsulate the IP in IP packet and forward the inner IP packet. This may result in IP packets bypassing input access control lists (ACLs) configured on the affe
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
bugzilla·2024-10-08·CVSS 5.3
CVE-2024-7595 [MEDIUM] CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
Bugzilla
CVE-2024-7596 networkmanager: UDP encapsulation protocol excessive trust
bugzilla·2024-10-08·CVSS 5.3
CVE-2024-7596 [MEDIUM] CVE-2024-7596 networkmanager: UDP encapsulation protocol excessive trust
CVE-2024-7596 networkmanager: UDP encapsulation protocol excessive trust
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
HackerOne
IP-in-IP protocol routes arbitrary traffic by default - CVE-2020-10136
hackerone·2021-08-15·CVSS 5.3
CVE-2020-10136 [MEDIUM] IP-in-IP protocol routes arbitrary traffic by default - CVE-2020-10136
IP-in-IP protocol routes arbitrary traffic by default - CVE-2020-10136
Many machines (150K-180K) on the internet accept and route IP over IP by default.
IP-in-IP encapsulation is a tunneling protocol specified in RFC 2003 that allows for IP packets to be encapsulated inside another IP packets. This is very similar to IPSEC VPNs in tunnel mode, except in the case of IP-in-IP, the traffic is unencrypted. As specified, the protocol unwraps the inner IP packet and forwards this packet through IP routing tables, potentially providing unexpected access to network paths available to the vulnerable device. An IP-in-IP device is considered to be vulnerable if it accepts IP-in-IP packets from any source to any destination without explicit configuration between the specified source and destination
Bugzilla
CVE-2020-10136 kernel: IP-in-IP protocol routes arbitrary traffic by default
bugzilla·2020-04-29·CVSS 5.3
CVE-2020-10136 [MEDIUM] CVE-2020-10136 kernel: IP-in-IP protocol routes arbitrary traffic by default
CVE-2020-10136 kernel: IP-in-IP protocol routes arbitrary traffic by default
A flaw was found in the IP-in-IP protocol. An unauthenticated attacker can use the IP-in-IP protocol to route network traffic through a vulnerable device, which can lead to spoofing, access control bypasses, and other unexpected network behaviors.
Discussion:
Statement:
The IP-in-IP encapsulation is 'in the clear' tunnel protocol between two hosts. When the module is loaded, the system will be in an 'any-to-any' routing state. It will accept any "IP in IP" packets and forward them through the system routing chains.
No authentication, encryption or restrictions is created between endpoints by the kernel module. Until a configuration rule is set, any system that can send "IP in IP" packets to an unconfigured sy
Tenable
CVE-2020-11896, CVE-2020-11897, CVE-2020-11901: Ripple20 Zero-Day Vulnerabilities in Treck TCP/IP Libraries Disclosed
blogs_tenable·2020-06-16·CVSS 10.0
[CRITICAL] CVE-2020-11896, CVE-2020-11897, CVE-2020-11901: Ripple20 Zero-Day Vulnerabilities in Treck TCP/IP Libraries Disclosed
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2020-10136: IP-in-IP Packet Processing Vulnerability Could Lead to DDoS, Network Access Bypass and Information Disclosure
blogs_tenable·2020-06-02·CVSS 5.3
[MEDIUM] CVE-2020-10136: IP-in-IP Packet Processing Vulnerability Could Lead to DDoS, Network Access Bypass and Information Disclosure
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://datatracker.ietf.org/doc/html/rfc6169https://kb.cert.org/vuls/id/636397/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-ipip-dos-kCT9X4https://www.digi.com/resources/securityhttps://www.kb.cert.org/vuls/id/636397https://datatracker.ietf.org/doc/html/rfc6169https://kb.cert.org/vuls/id/636397/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-ipip-dos-kCT9X4https://www.digi.com/resources/securityhttps://www.kb.cert.org/vuls/id/199397https://www.kb.cert.org/vuls/id/636397
2020-06-02
Published