Lucene search

K
cveFreebsdCVE-2020-7451
HistoryApr 28, 2020 - 8:15 p.m.

CVE-2020-7451

2020-04-2820:15:12
CWE-908
freebsd
web.nvd.nist.gov
43
cve-2020-7451
freebsd
tcp syn-ack
vulnerability
kernel memory disclosure
ipv6
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

35.9%

In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE before 11.3-RELEASE-p7, a TCP SYN-ACK or challenge TCP-ACK segment over IPv6 that is transmitted or retransmitted does not properly initialize the Traffic Class field disclosing one byte of kernel memory over the network.

Affected configurations

Nvd
Node
freebsdfreebsdMatch11.3-
OR
freebsdfreebsdMatch11.3p1
OR
freebsdfreebsdMatch11.3p2
OR
freebsdfreebsdMatch11.3p3
OR
freebsdfreebsdMatch11.3p4
OR
freebsdfreebsdMatch11.3p5
OR
freebsdfreebsdMatch11.3p6
OR
freebsdfreebsdMatch12.1-
OR
freebsdfreebsdMatch12.1p1
OR
freebsdfreebsdMatch12.1p2
VendorProductVersionCPE
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:-:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p1:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p2:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p3:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p4:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p5:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p6:*:*:*:*:*:*
freebsdfreebsd12.1cpe:2.3:o:freebsd:freebsd:12.1:-:*:*:*:*:*:*
freebsdfreebsd12.1cpe:2.3:o:freebsd:freebsd:12.1:p1:*:*:*:*:*:*
freebsdfreebsd12.1cpe:2.3:o:freebsd:freebsd:12.1:p2:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "FreeBSD",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, 11.3-RELEASE before 11.3-RELEASE-p7"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

35.9%