CVE-2020-13401: Input Validation
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAPNETRAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Other sources
Docker creates network bridges that accept IPv6 router advertisements by default. An attacker able to execute code in a container could exploit this to spoof rogue IPv6 router advertisements to perform a MitM attack against the host network.
Docker Docker CE is vulnerable to a man-in-the-middle attack, caused by improper validation of router advertisements. By sending rogue router advertisements, an attacker could exploit this vulnerability using man-in-the-middle techniques to gain access to the communication channel between endpoints to obtain sensitive information or further compromise the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-13401.
What is the severity level of CVE-2020-13401?
CVE-2020-13401 has a severity level of high.
Which software versions are affected by CVE-2020-13401?
IBM Security Guardium versions up to 11.3 and Docker Engine versions up to 19.03.11 are affected by CVE-2020-13401.
What is the impact of CVE-2020-13401?
CVE-2020-13401 allows an attacker to perform man-in-the-middle attacks and gain access to the communication channel between endpoints.
How can I fix CVE-2020-13401?
To fix CVE-2020-13401, update Docker Engine to version 19.03.11.