The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt
https://cert-portal.siemens.com/productcert/pdf/ssa-631949.pdf
https://jsof-tech.com/vulnerability-disclosure-policy/
https://security.netapp.com/advisory/ntap-20200625-0006/
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04012en_us
https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities
https://www.jsof-tech.com/ripple20/
https://www.kb.cert.org/vuls/id/257161
Source: MITRE
Published: 2020-06-17
Updated: 2020-07-22
Type: CWE-20
Base Score: 9.3
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 8.6
Severity: HIGH
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Impact Score: 6
Exploitability Score: 3.9
Severity: CRITICAL
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
140770 | HP iLO 3 < 1.93 / HP iLO 4 < 2.75 / HP iLO 5 < 2.18 Ripple20 Multiple vulnerabilities | Nessus | CGI abuses | high |
139545 | Multiple Vulnerabilities in Treck IP Stack Affecting Cisco Products: June 2020 (cisco-sa-treck-ip-stack-JyBQ5GyC) | Nessus | CISCO | critical |
137702 | Treck TCP/IP stack multiple vulnerabilities. (Ripple20) | Nessus | Misc. | critical |