Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact Low
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.24274.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Nexus 1000v
Subscribe
Nexus 1000ve
Subscribe
Nexus 3016
Subscribe
Nexus 3048
Subscribe
Nexus 3064
Subscribe
Nexus 3064-t
Subscribe
Nexus 3132q
Subscribe
Nexus 3172
Subscribe
Nexus 5010
Subscribe
Nexus 5020
Subscribe
Nexus 5548p
Subscribe
Nexus 5548up
Subscribe
Nexus 5596t
Subscribe
Nexus 5596up
Subscribe
Nexus 56128p
Subscribe
Nexus 5624q
Subscribe
Nexus 5648q
Subscribe
Nexus 5672up
Subscribe
Nexus 5696q
Subscribe
Nexus 6001
Subscribe
Nexus 6004
Subscribe
Nexus 7000
Subscribe
Nexus 7700
Subscribe
Nexus 92304qc
Subscribe
Nexus 92348gc-x
Subscribe
Nexus 9236c
Subscribe
Nexus 9272q
Subscribe
Nexus 93108tc-ex
Subscribe
Nexus 93108tc-fx
Subscribe
Nexus 93120tx
Subscribe
Nexus 93128tx
Subscribe
Nexus 93180lc-ex
Subscribe
Nexus 93180yc-ex
Subscribe
Nexus 93180yc-fx
Subscribe
Nexus 93216tc-fx2
Subscribe
Nexus 93240yc-fx2
Subscribe
Nexus 9332c
Subscribe
Nexus 9332pq
Subscribe
Nexus 93360yc-fx2
Subscribe
Nexus 9336c-fx2
Subscribe
Nexus 9336pq Aci Spine
Subscribe
Nexus 9348gc-fxp
Subscribe
Nexus 9364c
Subscribe
Nexus 9372px
Subscribe
Nexus 9372px-e
Subscribe
Nexus 9372tx
Subscribe
Nexus 9372tx-e
Subscribe
Nexus 9396px
Subscribe
Nexus 9396tx
Subscribe
Nexus 9504
Subscribe
Nexus 9508
Subscribe
Nexus 9516
Subscribe
Nx-os
Subscribe
Ucs 6248up
Subscribe
Ucs 6296up
Subscribe
Ucs 6324
Subscribe
Ucs 6332
Subscribe
Ucs 6332-16up
Subscribe
Ucs Manager
Subscribe
Unified Computing System
Subscribe
|
|
Digi
Subscribe
|
Saros
Subscribe
|
|
Hp
Subscribe
|
X3220nr Firmware
Subscribe
|
|
Treck
Subscribe
|
Tcp\/ip
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
|
Configuration 10 [-]
|
No data.
No data.
No advisories yet.
Solution
Customers should apply the latest patch provided by the affected vendor that addresses this issue and prevents unspecified IP-in-IP packets from being processed. Devices manufacturers are urged to disable IP-in-IP in their default configuration and require their customers to explicitly configure IP-in-IP as and when needed.
Workaround
Users can block IP-in-IP packets by filtering IP protocol number 4. Note this filtering is for the IPv4 Protocol (or IPv6 Next Header) field value of 4 and not IP protocol version 4 (IPv4).
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-11-03T20:33:32.981Z
Reserved: 2020-03-05T00:00:00.000Z
Link: CVE-2020-10136
No data.
Status : Modified
Published: 2020-06-02T09:15:09.967
Modified: 2025-11-03T21:15:39.860
Link: CVE-2020-10136
OpenCVE Enrichment
No data.