CVE-2020-25705
HIGHLinux Kernel < 5.10.0 - UDP Port Scan via ICMP Packet Source Port Prediction
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2020-25705. PoCs published by tdwyer, nanopathi.
AI-analyzed exploit summary This repository contains an incomplete PoC for CVE-2020-25705, a DNS cache poisoning vulnerability. The code outlines an algorithm for identifying open UDP ports and spoofing DNS responses but lacks functional implementation details.
Description
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: Version
Exploits (3)
This repository contains an incomplete PoC for CVE-2020-25705, a DNS cache poisoning vulnerability. The code outlines an algorithm for identifying open UDP ports and spoofing DNS responses but lacks functional implementation details.
The repository contains only documentation files and build scripts from a Linux kernel tree, with no actual exploit code or technical analysis related to CVE-2020-25705.
The repository contains documentation files from a Linux kernel version 4.19.72, specifically related to ABI stability, admin guides, and hardware-specific documentation. No exploit code or proof-of-concept is present in the provided files.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N