10
CVSSv2

CVE-2020-11897

Published: 17/06/2020 Updated: 22/07/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Treck TCP/IP stack prior to 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

treck tcp\\/ip

Vendor Advisories

A set of previously unknown vulnerabilities on the Treck IP stack implementation were disclosed on June 16, 2020 The vulnerabilities are collectively known as Ripple20 Exploitation of these vulnerabilities could result in remote code execution, denial of service (DoS), or information disclosure, depending on the specific vulnerability This advis ...

Github Repositories

Ripple20 Critical Vulnerabilities - Detection Logic and Signatures

Ripple20 Critical Vulnerabilities - Detection Logic and Signatures McAfee Advanced Threat Research Steve Povolny, Douglas McKee, Mark Bereza, D Kevin McGrath This document has been prepared by McAfee Advanced Threat Research in collaboration with JSOF who discovered and responsibly disclosed the vulnerabilities It is intended to serve as a joint research effort to produce val

Recent Articles

Psst.. You may want to patch this under-attack data-leaking Cisco bug – and these Ripple20 hijack flaws
The Register • Shaun Nichols in San Francisco • 25 Jul 2020

Plus: US govt sounds the alarm on industrial equipment attacks

In Brief Cisco this week emitted fixes for potentially serious vulnerabilities, one of which is already being exploited in the wild. The under-attack bug is CVE-2020-3452, a path-traversal flaw in Switchzilla's Adaptive Security Appliance and Firepower Threat Defense software that can be used to "read sensitive files on a targeted system." While there was no publicly available exploit code for the high-severity bug when first publicized, a day after issuing its advisory, Cisco said the flaw was ...