Lucene search

K

Treck Security Vulnerabilities

cve
cve

CVE-2020-10136

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

5.3CVSS

5.2AI Score

0.015EPSS

2020-06-02 09:15 AM
104
4
cve
cve

CVE-2020-11896

The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.

10CVSS

9.4AI Score

0.054EPSS

2020-06-17 11:15 AM
347
In Wild
2
cve
cve

CVE-2020-11897

The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.

10CVSS

9.3AI Score

0.014EPSS

2020-06-17 11:15 AM
173
In Wild
cve
cve

CVE-2020-11898

The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.

9.1CVSS

9.1AI Score

0.026EPSS

2020-06-17 11:15 AM
157
In Wild
cve
cve

CVE-2020-11899

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

5.4CVSS

7.2AI Score

0.003EPSS

2020-06-17 11:15 AM
1001
In Wild
3
cve
cve

CVE-2020-11900

The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.

8.2CVSS

8.8AI Score

0.01EPSS

2020-06-17 11:15 AM
200
In Wild
cve
cve

CVE-2020-11901

The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.

9CVSS

9.2AI Score

0.028EPSS

2020-06-17 11:15 AM
218
In Wild
2
cve
cve

CVE-2020-11902

The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.

7.3CVSS

8.1AI Score

0.004EPSS

2020-06-17 11:15 AM
127
In Wild
cve
cve

CVE-2020-11903

The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.

6.5CVSS

7.6AI Score

0.002EPSS

2020-06-17 11:15 AM
99
In Wild
cve
cve

CVE-2020-11904

The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.

7.3CVSS

8.2AI Score

0.006EPSS

2020-06-17 11:15 AM
114
In Wild
cve
cve

CVE-2020-11905

The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.

6.5CVSS

7.6AI Score

0.002EPSS

2020-06-17 11:15 AM
118
In Wild
cve
cve

CVE-2020-11906

The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.

6.3CVSS

7.5AI Score

0.002EPSS

2020-06-17 11:15 AM
160
In Wild
cve
cve

CVE-2020-11907

The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.

6.3CVSS

7.4AI Score

0.002EPSS

2020-06-17 11:15 AM
151
In Wild
cve
cve

CVE-2020-11908

The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.

4.3CVSS

6.4AI Score

0.002EPSS

2020-06-17 11:15 AM
106
In Wild
cve
cve

CVE-2020-11909

The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.

5.3CVSS

6.9AI Score

0.006EPSS

2020-06-17 11:15 AM
116
In Wild
cve
cve

CVE-2020-11910

The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.

5.3CVSS

6.9AI Score

0.005EPSS

2020-06-17 11:15 AM
193
In Wild
2
cve
cve

CVE-2020-11911

The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.

5.3CVSS

7AI Score

0.003EPSS

2020-06-17 11:15 AM
149
In Wild
cve
cve

CVE-2020-11912

The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.

5.3CVSS

6.9AI Score

0.004EPSS

2020-06-17 11:15 AM
153
In Wild
cve
cve

CVE-2020-11913

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

5.3CVSS

7AI Score

0.005EPSS

2020-06-17 11:15 AM
111
In Wild
cve
cve

CVE-2020-11914

The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.

4.3CVSS

6.5AI Score

0.002EPSS

2020-06-17 11:15 AM
162
In Wild
cve
cve

CVE-2020-25066

A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.

10CVSS

9.8AI Score

0.014EPSS

2020-12-22 10:15 PM
98
8
cve
cve

CVE-2020-27336

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a packet sent by an unauthenticated remote attacker could result in an out-of-bounds read of up to three bytes via network access.

5.3CVSS

7AI Score

0.002EPSS

2020-12-22 10:15 PM
84
9
cve
cve

CVE-2020-27337

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to cause an Out of Bounds Write, and possibly a Denial of Service via network access.

7.3CVSS

7.5AI Score

0.002EPSS

2020-12-22 10:15 PM
114
10
cve
cve

CVE-2020-27338

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows an unauthenticated remote attacker to cause an Out of Bounds Read, and possibly a Denial of Service via adjacent network access.

7.1CVSS

8.1AI Score

0.001EPSS

2020-12-22 10:15 PM
73
6