ZeroHour

Vulnerabilities

24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-27337
+2 in the same advisory: …27338 …27336
An issue was discovered in Treck IPv6 before 6.0.1.68.

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to cause an Out of Bounds Write, and possibly a Denial of Service via network access.

NVD description · AI analysis pending
7.3
group max
1%
  • treck ipv6
CVE-2020-25066
A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibl

A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.

NVD description · AI analysis pending
9.83%
  • treck tcp\/ip
CVE-2020-11896
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.

The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.

NVD description · AI analysis pending
10.0
group max
37% PoC
  • treck tcp\/ip
CVE-2020-11899
Out-of-Bounds Read in Treck TCP/IP Stack (IPv6) Affecting Dell Wyse Thin Clients

CVE-2020-11899 is an out-of-bounds read (CWE-125) in the IPv6 implementation of the Treck TCP/IP stack, present in versions before 6.0.1.66. It is triggered when a device running the vulnerable stack processes specially crafted IPv6 traffic; the CVSS vector indicates an adjacent-network attacker requires no privileges or user interaction, with low integrity and availability impacts and no confidentiality impact. Because the Treck TCP/IP stack is embedded software licensed into many vendors' products, affected products include the Treck stack itself and, per this data, Dell Wyse 5030, Wyse 5050 All-in-One, and Wyse 7030 thin-client firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), a public proof-of-concept reference exists via JSOF's Ripple20 research page, and EPSS assigns an 18.6% probability of exploitation within 30 days (97th percentile); ransomware use is unknown.

Do: Upgrade the Treck TCP/IP stack to 6.0.1.66 or later and apply the Dell firmware updates for Wyse 5030, Wyse 5050 All-in-One, and Wyse 7030 per vendor instructions, which is the CISA KEV required action for federal agencies. Inventory embedded, IoT/OT, and thin-client assets that may bundle the Treck stack, and restrict untrusted IPv6 traffic on adjacent network segments where upgrades are not yet available. Check additional vendors' advisories as well, since the Treck stack ships in many third-party products beyond those listed here.

5.419% KEV PoC
  • Treck TCP/IP stack (IPv6) before 6.0.1.66
  • Dell Wyse 5030 firmware
  • Dell Wyse 5050 All-in-One firmware
  • +1 more
masshundreds of thousands to millions of embedded devices running the Treck TCP/IP stack, including enterprise fleets of the listed Dell Wyse thin clients
CVE-2020-10136
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

NVD description · AI analysis pending
5.329%
  • cisco nx-os
  • cisco ucs manager
  • cisco saros
  • +1 more