IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Nx Os | — | Upgrade to the latest version of Cisco NX-OS to resolve this vulnerability. | Jun 15, 2020 | Jun 2, 2020 |
| Cisco Ucs_device | — | Upgrade Cisco UCS to version 4.0(4i)Upgrade Cisco UCS to version 3.2(3o)Upgrade Cisco UCS to version 4.1(1d) | Jun 17, 2020 | Jun 2, 2020 |
| Cisco Ucs_manager | — | Upgrade to the latest version of UCS Manager to resolve this vulnerability. | Sep 3, 2024 | Jun 1, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub