PT-2020-6613 · Treck · Treck Tcp/Ip Stack
Published
2020-06-16
·
Updated
2024-07-24
·
CVE-2020-11899
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Treck TCP/IP stack versions prior to 6.0.1.66
Description
The issue is related to an Out-of-bounds Read in the IPv6 implementation of the Treck TCP/IP stack. This is due to insufficient input validation, which can allow an attacker to gain unauthorized access to protected information.
Recommendations
For versions prior to 6.0.1.66, update to version 6.0.1.66 or later to resolve the issue. As a temporary workaround, consider restricting access to the IPv6 functionality until a patch is applied.
Exploit
Fix
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Treck Tcp/Ip Stack