
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-28362 affects Go programming language versions before 1.14.12 and 1.15.x before 1.15.4. The vulnerability was discovered and disclosed in November 2020, impacting systems using the Go programming language's math/big package. The vulnerability affects multiple software products that incorporate Go, including various NetApp products, Arista network devices, and other systems using the affected Go versions (NVD, Golang Notice).
The vulnerability exists in the math/big package of Go's standard library and can cause a panic during recursive division of very large numbers. The vulnerability has a CVSS v3.1 Base Score of 7.5 (HIGH) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue specifically affects math/big.Int methods including Div, Exp, DivMod, Quo, Rem, QuoRem, Mod, ModInverse, ModSqrt, Jacobi, and GCD when provided with crafted large inputs (Golang Notice, Arista Advisory).
When successfully exploited, this vulnerability can lead to a Denial of Service (DoS) condition. The vulnerability affects applications that use the math/big package via TLS connections or client certificate authentication. In network devices and applications, this can result in agent crashes, service disruptions, and impact overall product functionality (NetApp Advisory, Arista Advisory).
The primary mitigation is to upgrade to Go version 1.14.12 or 1.15.5 or later. For network devices and applications, it is recommended to restrict TLS connections to trusted sources using Control-Plane ACLs or iptables rules. As a security best practice, TLS connections should only be accepted from trusted sources (Arista Advisory, NetApp Advisory).
Multiple vendors including NetApp, Arista, and Red Hat released security advisories and patches for their affected products. The vulnerability was initially reported by the Go Ethereum team and the OSS-Fuzz project, leading to a coordinated response from the Go development team (Golang Notice).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."