Junglewise Threat Intelligence

CVE-2020-11899: Treck TCP/IP stack Out-of-Bounds Read Vulnerability

CVE-2020-11899 · Severity: critical · CVSS 5.4 · Exploited in the wild · Published 2022-03-03

Technologies: Treck TCP/IP Stack.

Executive brief

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. This flaw allows an attacker to potentially cause a denial-of-service or read sensitive information via network-adjacent access.

Affected products

  • Treck TCP/IP stack before 6.0.1.66

Timeline

  • 2020-06-16: disclosed: Initial disclosure of Ripple20 vulnerabilities.
  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: advisory: NVD publication date.
  • 2022-03-03: exploited: Confirmed as exploited in the wild by CISA.