EXPOSURES › CVE-2020-11899
CVE-2020-11899
HIGH ⌖ ON CISA KEV · EXPLOITEDTreck TCP/IP stack IPv6 out-of-bounds read vulnerability was actively exploited in the wild.
The Treck TCP/IP stack contained an IPv6 out-of-bounds read vulnerability that was actively exploited in the wild, indicating a failure to patch known issues before exploitation. DIB organizations must ensure all network stack components are regularly patched and monitored for KEV-listed vulnerabilities to prevent similar exposures. This failure highlights the risk of relying on unpatched network infrastructure, which can lead to data breaches or system compromise.
Shame score — The vulnerability was actively exploited in the wild, demonstrating a failure to patch a known issue before it was exploited, which is a severe and avoidable security lapse.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.