GHSA-59qg-grp7-5r73 · Severity: medium · Ecosystem: go — Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host (via ipv6.disable=1 on the kernel cmdline), it will be either unconfigured or configured on some interfaces, but it's pretty likely that ipv6 forwarding is disabled, ie /proc/sys/net/ipv6/conf//forwarding == 0. Also by default, /proc/sys/net/ipv6/conf//accept_ra == 1. The combination of these 2 sysctls means that the host accepts router advertisements and configure the IPv6 stack using them. By sending rogue router advertisements, an attacker can reconfigure the host to redirect part or all of the IPv6 traffic of the host to the attacker controlled container. Even if there was no IPv6 traffic before, if the DNS returns A (IPv4) and AAAA (IPv6) records, many HTTP libraries will try to connect via IPv6 first then fallback to IPv4, giving an opportunity to the attacker to respond. If by chance you also have on the host a vulnerability like last year's RCE in apt (CVE-2019-3462), you can now escalate to the host. Weave Net version 2.6.3 disables the accept_ra option on the veth devices that it creates.
Conclusion & alert: CVE-2020-11091 is rated Low Risk (35.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.17%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-17 | 0.05% | 0.17% | +0.12% |
| 2 | 2023-03-07 | 0.89% | 0.05% | -0.83% |
| 3 | 2022-04-01 | — | 0.89% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.8 | 3.1 | MEDIUM |
|
1.3 | 4.0 | [email protected] |
| 5.8 | 3.1 | MEDIUM |
|
1.3 | 4.0 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-59qg-grp7-5r73 · Severity: medium · Ecosystem: go — Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2020-11091 medium priority: Ubuntu including 1 source packages (golang-github-weaveworks-mesh-dev), 6 status rows across 6 suites (bionic, eoan, focal, trusty, upstream, xenial): DNE 5, needs-triage 1. | https://ubuntu.com/security/CVE-2020-11091 |
| URL | Tags |
|---|---|
| https://github.com/weaveworks/weave/commit/15f21f1899060f7716c70a8555a084e836f39a60 | Patch Third Party Advisory |
| https://github.com/weaveworks/weave/security/advisories/GHSA-59qg-grp7-5r73 | Third Party Advisory |