CVE-2020-11899

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
References
Link Resource
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt Third Party Advisory
https://cwe.mitre.org/data/definitions/125.html Technical Description
https://jsof-tech.com/vulnerability-disclosure-policy/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20200625-0006/ Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC Third Party Advisory
https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html Third Party Advisory
https://www.jsof-tech.com/ripple20/ Exploit Third Party Advisory
https://www.kb.cert.org/vuls/id/257161 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/257161/ Mitigation Third Party Advisory US Government Resource
https://www.treck.com Product Vendor Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt Third Party Advisory
https://cwe.mitre.org/data/definitions/125.html Technical Description
https://jsof-tech.com/vulnerability-disclosure-policy/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20200625-0006/ Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC Third Party Advisory
https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html Third Party Advisory
https://www.jsof-tech.com/ripple20/ Exploit Third Party Advisory
https://www.kb.cert.org/vuls/id/257161 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/257161/ Mitigation Third Party Advisory US Government Resource
https://www.treck.com Product Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:treck:tcp\/ip:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:wyse_5050_all-in-one_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5050_all-in-one:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:wyse_7030_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_7030:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dell:wyse_5030_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5030:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-06-17 11:15

Updated : 2025-03-14 17:27


NVD link : CVE-2020-11899

Mitre link : CVE-2020-11899

CVE.ORG link : CVE-2020-11899


JSON object : View

Products Affected

dell

  • wyse_5030_firmware
  • wyse_5050_all-in-one_firmware
  • wyse_5050_all-in-one
  • wyse_7030
  • wyse_7030_firmware
  • wyse_5030

treck

  • tcp\/ip
CWE
CWE-125

Out-of-bounds Read