CVE-2020-11899
בינונית 5.4 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Treck TCP/IP stack Out-of-Bounds Read Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
מדדים
- CVSS 3.1
-
5.4 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L - EPSS — סבירות ניצול
- 19% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-125
מוצרים מושפעים
treck: tcp\/ip; dell: wyse 5050 all-in-one firmware; dell: wyse 5050 all-in-one; dell: wyse 7030 firmware; dell: wyse 7030; dell: wyse 5030 firmware; dell: wyse 5030
קישורים
- https://www.treck.com ProductVendor Advisory
- https://www.treck.com ProductVendor Advisory
- https://www.jsof-tech.com/ripple20/ Broken LinkExploitThird Party Advisory
- https://www.jsof-tech.com/ripple20/ Broken LinkExploitThird Party Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt Broken LinkThird Party Advisory
- https://cwe.mitre.org/data/definitions/125.html Technical Description
- https://jsof-tech.com/vulnerability-disclosure-policy/ Broken LinkThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200625-0006/ Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Third Party Advisory
- https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripp… Third Party Advisory