Skip to main content

IP-in-IP Invalid Decapsulation Vulnerability

Security researchers have disclosed details of an invalid decapsulation vulnerability affecting the IP Encapsulation within IP (IETF RFC 2003) protocol. They claim that an unauthenticated remote attacker could exploit this vulnerability to arbitrarily reroute network traffic through an affected system.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security researchers have disclosed details of an invalid decapsulation vulnerability affecting the IP Encapsulation within IP (IETF RFC 2003) protocol. They claim that an unauthenticated remote attacker could exploit this vulnerability to arbitrarily reroute network traffic through an affected system.


Affected platforms

The following platforms are known to be affected:

  • All networking products implementing IP-in-IP encapsulation as specified in IETF RFC 2003

Threat details

By default, traffic sent through an IP-in-IP tunnel is unencrypted, with the protocol using the address packet to forward on the tracker using routing tables. If an IP-in-IP system is configured to accept traffic from any source, a remote user can interface directly with the tunnel by sending specially crafted packets. They may then force the tunnel to decapsulate traffic at any point, redirect traffic into or away from an affected system, bypass network-level access control lists, or use and affected system to perform reflective distributed denial-of-service attacks.

For further information:


Remediation steps

Type Step

Affected organisations are encouraged to contact their relevant suppliers to obtain and apply any necessary updates immediately.

Organisations may also consider blocking IP-in-IP packets by filtering IP protocol number 4. Please note that this filtering is applied for the IPv4 protocol field value 4 and not IPv4 itself.



CVE Vulnerabilities

Last edited: 29 June 2021 12:01 pm