ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-36516

An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.
5.9
CVSS
5.5
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityHigh
RequirementsPresent
PrivilegesLow
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityNone
IntegrityHigh
AvailabilityLow
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21PoCE: U→P2.3 → 5.5
2026-07-21nvdAV: P→N, PR: H→L, UI: A→N, VI: N→H, VA: N→L0.0 → 2.3
2026-07-21cve.orginitial, patch: Unavailable0.0

Affected Software
VendorProductVersion
linuxlinux_kernel≤ 5.6.11
netappbootstrap_osAll versions
netappcloud_volumes_ontap_mediatorAll versions
netappe-series_santricity_os_controller≥ 11.0
netapph300e_firmwareAll versions
netapph300s_firmwareAll versions
netapph410c_firmwareAll versions
netapph410s_firmwareAll versions
netapph500e_firmwareAll versions
netapph500s_firmwareAll versions
netapph610c_firmwareAll versions
netapph610s_firmwareAll versions
netapph615c_firmwareAll versions
netapph700e_firmwareAll versions
netapph700s_firmwareAll versions
netappsolidfire_\&_hci_management_nodeAll versions
netappsolidfire\,_enterprise_sds_\&_hci_storage_nodeAll versions
Published: 2022-02-26