CVE-2020-11899: Treck TCP/IP stack Out-of-Bounds Read Vulnerability
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
Other sources
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11899?
CVE-2020-11899 is a vulnerability in the Treck TCP/IP stack that allows for an out-of-bounds read in the IPv6 subsystem.
What is the severity of CVE-2020-11899?
The severity of CVE-2020-11899 is medium with a CVSS score of 5.4.
Which software is affected by CVE-2020-11899?
The Treck TCP/IP stack IPv6 version 6.0.1.66 and earlier are affected by CVE-2020-11899.
How can I fix CVE-2020-11899?
To fix CVE-2020-11899, it is recommended to upgrade to a version of the Treck TCP/IP stack that is not affected by the vulnerability.
Where can I find more information about CVE-2020-11899?
You can find more information about CVE-2020-11899 in the references provided: http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt, https://cwe.mitre.org/data/definitions/125.html, and https://jsof-tech.com/vulnerability-disclosure-policy/