Vulnerabilities > CVE-2020-25645

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE

Summary

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.

Vulnerable Configurations

Part Description Count
OS
Linux
4605
OS
Debian
2
OS
Opensuse
2
OS
Netapp
1
OS
Canonical
4
Application
Netapp
2
Hardware
Netapp
1