CVE-2020-8231
Vulnerability Scoring
Attack Complexity Details
- Attack Complexity: Low Impact
- Attack Vector: NETWORK
- Privileges Required: None
- Scope: UNCHANGED
- User Interaction: NONE
CIA Impact Definition
- Confidentiality: HIGH IMPACT
- Integrity:
- Availability:
CVE-2020-8231 Vulnerability Summary
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
Access Complexity Graph for CVE-2020-8231
Impact Analysis for CVE-2020-8231
CVE-2020-8231: Detailed Information and External References
EPSS
0.00389
EPSS %
0.73220
References
0.00389
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://curl.haxx.se/docs/CVE-2020-8231.html
- https://hackerone.com/reports/948876
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://security.gentoo.org/glsa/202012-14
- https://www.debian.org/security/2021/dsa-4881
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://curl.haxx.se/docs/CVE-2020-8231.html
- https://hackerone.com/reports/948876
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://security.gentoo.org/glsa/202012-14
- https://www.debian.org/security/2021/dsa-4881
- https://www.oracle.com/security-alerts/cpuapr2022.html
CWE
CWE-416
Vulnerable Configurations
-
cpe:2.3:a:haxx:libcurl:7.29.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.29.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.30.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.30.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.32.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.32.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.33.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.33.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.34.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.34.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.35.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.35.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.36.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.36.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.37.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.37.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.37.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.37.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.38.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.38.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.39:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.39:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.39.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.39.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.40.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.40.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.41.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.41.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.42:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.42:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.42.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.42.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.42.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.42.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.43.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.43.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.44.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.44.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.45.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.45.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.46.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.46.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.47.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.47.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.47.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.47.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.48.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.48.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.49.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.49.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.49.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.49.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.50.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.50.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.50.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.50.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.50.2:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.50.2:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.50.3:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.50.3:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.51.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.51.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.52.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.52.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.52.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.52.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.53.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.53.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.53.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.53.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.54.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.54.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.54.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.54.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.55.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.55.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.55.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.55.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.56.0:*:*:*:*:*:x86:*
cpe:2.3:a:haxx:libcurl:7.56.0:*:*:*:*:*:x86:*
-
cpe:2.3:a:haxx:libcurl:7.56.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.56.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.56.1:*:*:*:*:*:x86:*
cpe:2.3:a:haxx:libcurl:7.56.1:*:*:*:*:*:x86:*
-
cpe:2.3:a:haxx:libcurl:7.56.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.56.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.57.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.57.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.58.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.58.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.59.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.59.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.60.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.60.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.61.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.61.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.61.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.61.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.62.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.62.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.63.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.63.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.64.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.64.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.64.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.64.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.65.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.65.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.65.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.65.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.65.2:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.65.2:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.65.3:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.65.3:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.66.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.66.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.67.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.67.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.68.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.68.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.69.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.69.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.69.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.69.1:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.70.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.70.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.71.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.71.0:*:*:*:*:*:*:*
-
cpe:2.3:a:haxx:libcurl:7.71.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.71.1:*:*:*:*:*:*:*
-
cpe:2.3:a:siemens:sinec_infrastructure_network_services:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_infrastructure_network_services:-:*:*:*:*:*:*:*
-
cpe:2.3:a:siemens:sinec_infrastructure_network_services:1.0.1:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_infrastructure_network_services:1.0.1:-:*:*:*:*:*:*
-
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
-
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:8.2.0:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:8.2.6:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:8.2.6:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:8.2.7:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:8.2.7:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:8.2.8:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:8.2.8:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:8.2.9:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:8.2.9:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:8.2.10:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:8.2.10:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:8.2.11:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:8.2.11:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.0.0:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.0.1:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:9.0.2:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.0.2:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:9.0.3:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.0.3:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:9.0.4:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.0.4:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:9.0.5:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.0.5:*:*:*:*:*:*:*
-
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*
CVSS3 Source
nvd@nist.gov
CVSS3 Type
Primary
CVSS3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Protect Your Infrastructure: Combat Critical CVE Threats
Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.