LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-11899: Treck TCP/IP stack Out-of-Bounds Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
CVSS 5.4 · Medium⚠ Actively exploited (CISA KEV)
5.4
CVSS score
Medium
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-11899 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

CVE-2020-11899 is an out-of-bounds read vulnerability in the IPv6 handling of the Treck TCP/IP stack. An attacker who can send crafted IPv6 traffic to a device running the affected stack may cause it to read memory outside the intended bounds. For IT and security teams, this matters because Treck’s stack is commonly embedded in networked devices and industrial or IoT equipment; a successful attack can disrupt availability or leak information from process memory, depending on how the product uses the stack. Confirm exact impact and fixed releases against the vendor advisory for your specific product.

How it works

The weakness is classified as CWE-125 (out-of-bounds read). In plain terms, the IPv6 parsing or processing path in the Treck TCP/IP stack does not adequately ensure that a read stays within a valid buffer. When malformed or unexpected IPv6 input is processed, the stack may access memory beyond the allocated region.

An attacker abuses this by sending specially crafted IPv6 packets toward a reachable interface that uses the vulnerable stack. The goal is to trigger the faulty read. Outcomes for this class of flaw typically include denial of service (crash or hang) or disclosure of adjacent memory contents; the precise result depends on the device’s memory layout and how the vendor integrated the stack. No public exploit mechanics beyond the CISA summary—that the stack contains an IPv6 out-of-bounds read—are assumed here. Treat any deeper technical claims as unverified until you review the vendor’s advisory and your own lab testing.

Am I affected? How to find it in your systems

Treck TCP/IP is an embedded networking stack, so it usually appears inside firmware of routers, gateways, printers, medical or industrial controllers, and other appliances rather than as a standalone package on general-purpose servers. Inventory is therefore product- and firmware-centric.

How to remediate

Patching is the primary fix. Apply the updates supplied by the device or software vendor that incorporate a corrected Treck TCP/IP stack, following the vendor’s instructions exactly as CISA directs. There is no universal version number that applies to every product; each OEM integrates and ships the stack on its own schedule.

If you can't patch immediately

Until a vendor update can be deployed, reduce exposure with compensating controls appropriate to an embedded IPv6 stack flaw:

These steps lower likelihood and impact but do not replace the vendor patch.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and, in some environments, to broader network intrusion or data exposure. Ransomware use of this CVE is not documented in the provided facts. If you suspect exploitation, isolate affected devices, preserve logs and memory captures where feasible, and follow your incident-response process, including vendor and forensic support as needed. As a routine hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal data associated with your organization already appear in public breach corpora, then force password resets and review access where hits are found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTreck TCP/IP stack · IPv6
WeaknessCWE-125
CVSS base score5.4 (Medium)
CVSS vectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
PublishedJun 17, 2020
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities