← Vulnerability feed

Vulnerability record · CVE-2020-10136 · published 2 June 2020

CVE-2020-10136: Cisco nx-os authentication bypass by spoofing vulnerability

Cisco · Nx Os

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

5.3 CVSS 3.1 Medium EPSS 29% · top 1.9% CWE-290 · Authentication bypass by spoofing
5.3CVSS 3.1 base score, v2 5.0
29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
11References
17 Jun 2026Last modified by NVD

Description

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10136 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed6.7CVE-2024-20399Cisco NX-OS CLI command injection allows root command executionCisco NX-OS fails to properly validate arguments passed to specific configuration CLI commands, allowing OS command injection. An attacker who alread…KEVEPSS 4.3%analysed9.8CVE-2018-0310Cisco nx-os out-of-bounds read vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 4.1%9.8CVE-2018-0301Cisco nx-os improper input validation vulnerabilityA vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management int…EPSS 17%9.8CVE-2016-1453Cisco nx-os memory buffer overflow vulnerabilityBuffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote…EPSS 8.1%9.8CVE-2016-1341Cisco nx-os permissions and access controls vulnerabilityCisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to ga…EPSS 1.1%9.8CVE-2015-6435Cisco firepower extensible operating system os command injection vulnerabilityAn unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(…EPSS 8.7%9.1CVE-2021-1361Cisco nx-os vulnerabilityA vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switche…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2020-10136), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.