Insufficient verification of data authenticity in CNI Plugins - CVE-2020-10749

 

Insufficient verification of data authenticity in CNI Plugins - CVE-2020-10749

Published: July 24, 2020 / Updated: July 24, 2020


Vulnerability identifier: #VU31794
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10749
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a man-in-the-Middle attack.

The vulnerability exists due to insufficient verification of data authenticity in CNI plugins when processing IPV6 router advertisements. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.


Affected software

CNI Plugins
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Public Cloud
Opensuse
Fedora
containernetworking-plugins (Red Hat package)
cni-plugins
golang-github-containernetworking-plugins

How to mitigate CVE-2020-10749

Install updates from vendor's website.

CNI Plugins - update to 0.8.6
containernetworking-plugins (Red Hat package) - addressed in versions 0.8.3-3.el7_8, 0.8.6-1.rhaos4.2.el7, 0.8.6-1.rhaos4.2.el8, 0.8.6-1.rhaos4.3.el8, 0.8.6-1.rhaos4.4.el7, 0.8.6-1.rhaos4.4.el8
cni-plugins - update to 0.8.6-150000.1.7.1
golang-github-containernetworking-plugins - update to 0.9.0-1.fc32

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins