← All CVEs

CVE-2020-11899

medium · 5.4Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-17

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

5.4
CVSS
18.6%
EPSS (exploit prob.)
97th
EPSS percentile
2020-06-17
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
trecktcp/ip< 6.0.1.66
dellwyse_5050_all-in-one_firmwareall versions
dellwyse_5050_all-in-oneall versions
dellwyse_7030_firmwareall versions
dellwyse_7030all versions
dellwyse_5030_firmwareall versions
dellwyse_5030all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-11899