CVE-2020-10136: Cisco NX-OS

Medium severity, CVSS 5.3. EPSS: 28.5% chance of exploitation in the next 30 days.

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

Affected products

  • Cisco NX-OS: version 5.2(1)sk3(1.1) only; version 5.2(1)sk3(2.1) only; version 5.2(1)sk3(2.1a) only; version 5.2(1)sk3(2.2) only; version 5.2(1)sk3(2.2b) only; version 5.2(1)sm1(5.1) only; …
  • Cisco Ucs Manager: version 3.2(3n)a only
  • Cisco Unified Computing System: affected versions not specified
  • Digi Saros: before 8.1.0.1 (fixed in 8.1.0.1)
  • HP x3220nr Firmware: before 3.00.11.08 (fixed in 3.00.11.08)
  • Treck Tcp/ip: before 6.0.1.67 (fixed in 6.0.1.67)

Published 2020-06-02. Last modified 2026-06-17.