CVE-2020-25705 PUBLISHED

A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: Version

EPSS 1.06% · 77.5th percentile

Risk Scores

EPSS Score
1.06%
77.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-azure-fips0, 5.4.0-1022.22+fips1
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:18.04:LTSlinux-dell300x4.15.0-1009.13, 4.15.0-1006.10, 4.15.0-1007.11
Ubuntu:20.04:LTSlinux-riscv5.4.0-24.28, 5.4.0-33.37, 5.4.0-27.31
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-fips0, 4.15.0-1048.55, 4.15.0-1027.32
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1003.3, 0, 4.4.0-1012.16
Ubuntu:18.04:LTSlinux-gcp5.0.0-1026.27~18.04.1, 5.0.0-1029.30~18.04.1, 5.0.0-1031.32
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1048.51, 4.15.0-1037.39, 4.15.0-1040.42
Ubuntu:18.04:LTSlinux-gcp-5.35.3.0-1012.13~18.04.1, 5.3.0-1010.11~18.04.1, 5.3.0-1009.10~18.04.1
Ubuntu:18.04:LTSlinux4.15.0-62.69, 4.15.0-91.92, 4.15.0-96.97
Ubuntu:20.04:LTSlinux-oem-5.65.6.0-1031.32, 5.6.0-1028.28, 5.6.0-1027.27
Ubuntu:16.04:LTSlinux-hwe4.15.0-58.64~16.04.1, 4.15.0-60.67~16.04.1, 4.15.0-62.69~16.04.1
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:16.04:LTSlinux-aws4.4.0-1017.26, 4.4.0-1018.27, 4.4.0-1020.29
Ubuntu:18.04:LTSlinux-raspi24.15.0-1053.57, 4.15.0-1076.81, 4.15.0-1074.79
Ubuntu:18.04:LTSlinux-gcp-edge0, 4.18.0-1004.5~18.04.1, 4.18.0-1005.6~18.04.1
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1062.66, 4.4.0-1064.68, 4.4.0-1065.69
Ubuntu:18.04:LTSlinux-gcp-4.154.15.0-1090.103, 4.15.0-1088.101, 4.15.0-1087.100
Ubuntu:18.04:LTSlinux-oem4.15.0-1065.75, 0, 4.15.0-1002.3
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1023.26~18.04.1, 0, 5.0.0-1021.24~18.04.1

…and 53 more

Timeline

References

Open in Interactive Console →