PT-2020-6617 · Treck · Treck Tcp/Ip Stack

Published

2020-06-16

·

Updated

2025-09-30

·

CVE-2020-11909

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Treck TCP/IP stack versions prior to 6.0.1.66
Description The issue is related to insufficient input validation in the implementation of the IPv4 protocol stack. This can allow a remote attacker to gain unauthorized access to protected information. The problem is specifically an IPv4 Integer Underflow.
Recommendations For versions prior to 6.0.1.66, update to version 6.0.1.66 or later to resolve the issue. As a temporary workaround, consider restricting access to the IPv4 protocol stack until a patch is available.

Exploit

Fix

Integer Underflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01531
CVE-2020-11909

Affected Products

Treck Tcp/Ip Stack