CVE-2020-13401

Description

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

Risk Information

Base Score
6.0
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS Score
Exploitation Probability
12.87

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
docker.io security update(DSA-4716-1) docker.io_18.09.1+dfsg1-7.1+deb10u2_i386.debLinux
docker.io security update(DSA-4716-1) docker.io_18.09.1+dfsg1-7.1+deb10u2_amd64.debLinux
Docker-cli update (ELSA-2020-5739) docker-cli-19.03.11.ol-4.el7.x86_64.rpmLinux
Docker-engine update (ELSA-2020-5739) docker-engine-19.03.11.ol-4.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234