CVE Published: 02/06/2020 |
CVE Updated: 17/09/2024 |
CVE Year: 2020 Source: certcc |
Vendor: IETF |
Product: RFC2003 - IP Encapsulation within IP Status : PUBLISHED
CVE-2020-10136 Description
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.