PT-2020-5941 · Treck · Treck Tcp/Ip Stack

Published

2020-06-17

·

Updated

2021-07-21

·

CVE-2020-11901

CVSS v3.1

9.3

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Treck TCP/IP stack versions prior to 6.0.1.66
Description: The issue exists due to insufficient input validation in the Treck TCP/IP stack. It allows a remote attacker to execute arbitrary code using a specially crafted DNS response.
Recommendations: For versions prior to 6.0.1.66, update to version 6.0.1.66 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Out of bounds Read

Use of Insufficiently Random Values

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2021-02071
CVE-2020-11901

Affected Products

Treck Tcp/Ip Stack