The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
https://jsof-tech.com/vulnerability-disclosure-policy/
https://www.jsof-tech.com/ripple20/
https://www.kb.cert.org/vuls/id/257161/
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt
https://www.kb.cert.org/vuls/id/257161
https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities
Source: MITRE
Published: 2020-06-17
Updated: 2021-07-21
Type: CWE-20
Base Score: 9.3
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 8.6
Severity: HIGH
Base Score: 9
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Impact Score: 6
Exploitability Score: 2.2
Severity: CRITICAL