Skip to content
COOEY

EXPOSURES › CVE-2020-11899

CVE-2020-11899

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-11899 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatched

Treck TCP/IP stack IPv6 out-of-bounds read vulnerability was actively exploited in the wild.

The Treck TCP/IP stack contained an IPv6 out-of-bounds read vulnerability that was actively exploited in the wild, indicating a failure to patch known issues before exploitation. DIB organizations must ensure all network stack components are regularly patched and monitored for KEV-listed vulnerabilities to prevent similar exposures. This failure highlights the risk of relying on unpatched network infrastructure, which can lead to data breaches or system compromise.

Shame score — The vulnerability was actively exploited in the wild, demonstrating a failure to patch a known issue before it was exploited, which is a severe and avoidable security lapse.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.