← back
CVE-2020-13597

Calico nodes IPv6 traffic redirection from route advertisment

CVSS 6 MEDIUMEPSS 0.9%CWE-201
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 Jun 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node accepting route advertisement by default, allowing the attacker to redirect full or partial network traffic from the node to the compromised pod.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →