Description
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: Version
Published: 2020-11-17
Score: 7.4 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2483-1 linux-4.19 security update
Debian DLA Debian DLA DLA-2494-1 linux security update
EUVD EUVD EUVD-2020-18360 A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: Version
Ubuntu USN Ubuntu USN USN-4657-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-4658-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-4659-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-4680-1 Linux kernel vulnerabilities
History

No history.

Subscriptions

Linux Linux Kernel
Redhat Enterprise Linux Rhel Aus Rhel E4s Rhel Eus Rhel Extras Rt Rhel Tus
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T15:40:36.596Z

Reserved: 2020-09-16T00:00:00.000Z

Link: CVE-2020-25705

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-17T02:15:13.427

Modified: 2024-11-21T05:18:31.810

Link: CVE-2020-25705

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-11-13T00:00:00Z

Links: CVE-2020-25705 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses