CVE-2020-8554General(kubernetes / communications_cloud_native_core_network_slice_selection_function)

LOWCVSS 5.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kubernetes communications_cloud_native_core_network_slice_selection_function systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-283

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • communications_cloud_native_core_network_slice_selection_function
  • communications_cloud_native_core_policy
  • communications_cloud_native_core_service_communication_proxy
  • kubernetes

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
communications_cloud_native_core_network_slice_selection_functioncommunications_cloud_native_core_policycommunications_cloud_native_core_service_communication_proxykubernetes

3 versions affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-16: 1Mentions · 2026-07-27: 1Patch / Workaround · 2026-07-27: 1Technical Details · 2026-07-27: 102-1607-27
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-161
General1
2026-07-271
Patch1
Full discourse2 posts
  • Amaresh Pelleti@amareswer
    Patch

    5/7 Watch this one: .spec.externalIPs is being phased out over several releases. It's tied to CVE-2020-8554, a man-in-the-middle risk. Not gone in 1.36, but start moving to LoadBalancer or Gateway API.

    Post summary

    The message highlights a man-in-the-middle risk from CVE‑2020‑8554 and advises users to stop using .spec.externalIPs and switch to LoadBalancer or Gateway API before version 1.36.

    1000014
    53 followersView on X
  • Mas73r@Mas73r
    General

    CVE-2020-8554 https://nvd.nist.gov/vuln/detail/cve-2020-8554

    Post summary

    The entry merely cites CVE-2020-8554 and links to its NVD page, providing no further detail or context.

    0000032
    470 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appkuberneteskubernetes---
Apporaclecommunications_cloud_native_core_network_slice_selection_function1.2.1--
Apporaclecommunications_cloud_native_core_policy1.15.0--
Apporaclecommunications_cloud_native_core_service_communication_proxy1.14.0--

Explore more