HIGH · 8.1

CVE-2020-14305

An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated ...

Vulnerability Description

An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 4.11.12
NetappCloud Backup-
NetappA250 Firmware-
NetappA250-
NetappFas 500F Firmware-
NetappFas 500F-
NetappAff 500F Firmware-
NetappAff 500F-
NetappSolidfire Baseboard Management Controller Firmware-
NetappSolidfire Baseboard Management Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-14305?

CVE-2020-14305 is a vulnerability with a CVSS score of 8.1 (HIGH). An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated ...

How severe is CVE-2020-14305?

CVE-2020-14305 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-14305?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Netapp Cloud Backup, Netapp A250 Firmware, Netapp A250, Netapp Fas 500F Firmware.