ZeroHour

CVE-2020-11899

KEV PoC mass

Out-of-Bounds Read in Treck TCP/IP Stack (IPv6) Affecting Dell Wyse Thin Clients

CISA: Treck TCP/IP stack Out-of-Bounds Read Vulnerability

CVSS 3.1
5.4 medium
EPSS
19%p97
Published
()
KEV added
AI analysis

CVE-2020-11899 is an out-of-bounds read (CWE-125) in the IPv6 implementation of the Treck TCP/IP stack, present in versions before 6.0.1.66. It is triggered when a device running the vulnerable stack processes specially crafted IPv6 traffic; the CVSS vector indicates an adjacent-network attacker requires no privileges or user interaction, with low integrity and availability impacts and no confidentiality impact. Because the Treck TCP/IP stack is embedded software licensed into many vendors' products, affected products include the Treck stack itself and, per this data, Dell Wyse 5030, Wyse 5050 All-in-One, and Wyse 7030 thin-client firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), a public proof-of-concept reference exists via JSOF's Ripple20 research page, and EPSS assigns an 18.6% probability of exploitation within 30 days (97th percentile); ransomware use is unknown.

What to do: Upgrade the Treck TCP/IP stack to 6.0.1.66 or later and apply the Dell firmware updates for Wyse 5030, Wyse 5050 All-in-One, and Wyse 7030 per vendor instructions, which is the CISA KEV required action for federal agencies. Inventory embedded, IoT/OT, and thin-client assets that may bundle the Treck stack, and restrict untrusted IPv6 traffic on adjacent network segments where upgrades are not yet available. Check additional vendors' advisories as well, since the Treck stack ships in many third-party products beyond those listed here.

Affected
Treck TCP/IP stack (IPv6)before 6.0.1.66
Dell Wyse 5030 firmware
Dell Wyse 5050 All-in-One firmware
Dell Wyse 7030 firmware
Estimated exposure
masshundreds of thousands to millions of embedded devices running the Treck TCP/IP stack, including enterprise fleets of the listed Dell Wyse thin clients — The Treck TCP/IP stack is licensed across dozens of hardware vendors and Ripple20-era public reporting described a very large embedded installed base, while the three named Dell Wyse thin-client models are typically deployed in large…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

CISA Known Exploited Vulnerability
Affected
Treck TCP/IP stack IPv6
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
treckdell
Products
tcp\/ip, wyse 5050 all-in-one firmware, wyse 7030 firmware, wyse 5030 firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

In the news