CVE-2020-11899
KEV PoC massOut-of-Bounds Read in Treck TCP/IP Stack (IPv6) Affecting Dell Wyse Thin Clients
CISA: Treck TCP/IP stack Out-of-Bounds Read Vulnerability
CVE-2020-11899 is an out-of-bounds read (CWE-125) in the IPv6 implementation of the Treck TCP/IP stack, present in versions before 6.0.1.66. It is triggered when a device running the vulnerable stack processes specially crafted IPv6 traffic; the CVSS vector indicates an adjacent-network attacker requires no privileges or user interaction, with low integrity and availability impacts and no confidentiality impact. Because the Treck TCP/IP stack is embedded software licensed into many vendors' products, affected products include the Treck stack itself and, per this data, Dell Wyse 5030, Wyse 5050 All-in-One, and Wyse 7030 thin-client firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), a public proof-of-concept reference exists via JSOF's Ripple20 research page, and EPSS assigns an 18.6% probability of exploitation within 30 days (97th percentile); ransomware use is unknown.
What to do: Upgrade the Treck TCP/IP stack to 6.0.1.66 or later and apply the Dell firmware updates for Wyse 5030, Wyse 5050 All-in-One, and Wyse 7030 per vendor instructions, which is the CISA KEV required action for federal agencies. Inventory embedded, IoT/OT, and thin-client assets that may bundle the Treck stack, and restrict untrusted IPv6 traffic on adjacent network segments where upgrades are not yet available. Check additional vendors' advisories as well, since the Treck stack ships in many third-party products beyond those listed here.
| Treck TCP/IP stack (IPv6) | before 6.0.1.66 |
| Dell Wyse 5030 firmware | — |
| Dell Wyse 5050 All-in-One firmware | — |
| Dell Wyse 7030 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
- Affected
- Treck TCP/IP stack IPv6
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown