PT-2020-5940 · Treck+1 · Treck Tcp/Ip Stack+1

Published

2020-06-17

·

Updated

2025-05-23

·

CVE-2020-11900

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions: Treck TCP/IP stack versions prior to 6.0.1.41
Description: The issue is related to a double free error in the implementation of IPv4 tunneling in the Treck TCP/IP stack. This could allow a remote attacker to cause a denial of service.
Recommendations: For versions prior to 6.0.1.41, update to version 6.0.1.41 or later to resolve the issue. As a temporary workaround, consider restricting access to the IPv4 tunneling functionality until a patch is available.

Exploit

Fix

Double Free

Weakness Enumeration

Related Identifiers

BDU:2021-02070
CVE-2020-11900

Affected Products

Hpe Ilo
Treck Tcp/Ip Stack