CVE-2020-13597
MEDIUMCalico < 2.6.2 - Information Disclosure
Title source: ruleDescription
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node accepting route advertisement by default, allowing the attacker to redirect full or partial network traffic from the node to the compromised pod.
Scores
CVSS v3
6.0
EPSS
0.0021
EPSS Percentile
43.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Classification
CWE
CWE-201
CWE-200
Status
published
Affected Products (4)
projectcalico/calico
< 2.6.2
projectcalico/calico
< 3.8.8
projectcalico/calico
projectcalico/calico
< 3.14.1Go
Timeline
Published
Jun 03, 2020
Tracked Since
Feb 18, 2026