CVE-2020-11899
treck tcp/ip, dell wyse 5050 all-in-one firmware, dell wyse 7030 firmware
Published 17 Jun 2020 · updated 17 Jun 2026 · Analyzed
5.4 Medium · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 17 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
References
- www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt · Broken Link, Third Party Advisory
- cwe.mitre.org/data/definitions/125.html · Technical Description
- jsof-tech.com/vulnerability-disclosure-policy/ · Broken Link, Third Party Advisory
- security.netapp.com/advisory/ntap-20200625-0006/ · Third Party Advisory
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC · Third Party Advisory
- www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities · Third Party Advisory
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html · Third Party Advisory
- www.jsof-tech.com/ripple20/ · Broken Link, Exploit, Third Party Advisory
- www.kb.cert.org/vuls/id/257161 · Third Party Advisory, US Government Resource
- www.kb.cert.org/vuls/id/257161/ · Mitigation, Third Party Advisory, US Government Resource
- www.treck.com/ · Product, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11899 · US Government Resource