treck records
24 published records for vendor treck.
Researcher profile
- Entered KEV
- 1 · 4.2%
- Weaponized
- 1 · 4.2%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- 624 days
Recurring classes
- CWE-125 Out-of-bounds Read9
- CWE-20 Improper Input Validation3
- CWE-787 Out-of-bounds Write2
- CWE-191 Integer Underflow (Wrap or Wraparound)2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-290 Authentication Bypass by Spoofing1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2020-11899Weaponized | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium5.4 | KEV | 18.6% | Jun 17, 2020 |
51Plan | CVE-2020-11896Proof of concept | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.treck · tcp\/ip · CWE-119 | Critical10.0 | — | 36.9% | Jun 17, 2020 |
43Plan | CVE-2020-11897No exploit | The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.treck · tcp\/ip · CWE-787 | Critical10.0 | — | 9.1% | Jun 17, 2020 |
42Plan | CVE-2020-11901No exploit | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.treck · tcp\/ip · CWE-125 | Critical9.0 | — | 21.1% | Jun 17, 2020 |
42Plan | CVE-2020-11898Proof of concept | The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers treck · tcp\/ip · CWE-119 | Critical9.1 | — | 18.9% | Jun 17, 2020 |
40Plan | CVE-2020-25066No exploit | A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/treck · tcp\/ip · CWE-787 | Critical9.8 | — | 3.5% | Dec 22, 2020 |
36Monitor | CVE-2020-11900No exploit | The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.treck · tcp\/ip · CWE-415 | High8.2 | — | 13.2% | Jun 17, 2020 |
32Monitor | CVE-2020-11902No exploit | The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.treck · tcp\/ip · CWE-125 | High7.3 | — | 9.3% | Jun 17, 2020 |
30Monitor | CVE-2020-10136Proof of concept | IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network trafficcisco · nx-os · CWE-290 | Medium5.3 | — | 28.5% | Jun 2, 2020 |
30Monitor | CVE-2020-11904No exploit | The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.treck · tcp\/ip · CWE-190 | High7.3 | — | 3.2% | Jun 17, 2020 |
29Monitor | CVE-2020-27337No exploit | An issue was discovered in Treck IPv6 before 6.0.1.68.treck · ipv6 · CWE-20 | High7.3 | — | 1.5% | Dec 22, 2020 |
28Monitor | CVE-2020-27338No exploit | An issue was discovered in Treck IPv6 before 6.0.1.68.treck · ipv6 · CWE-20 | High7.1 | — | 0.8% | Dec 22, 2020 |
27Monitor | CVE-2020-11903No exploit | The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium6.5 | — | 2.1% | Jun 17, 2020 |
27Monitor | CVE-2020-11905No exploit | The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium6.5 | — | 2.0% | Jun 17, 2020 |
26Monitor | CVE-2020-11907No exploit | The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.treck · tcp\/ip | Medium6.3 | — | 2.0% | Jun 17, 2020 |
26Monitor | CVE-2020-11906No exploit | The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.treck · tcp\/ip · CWE-191 | Medium6.3 | — | 2.0% | Jun 17, 2020 |
24Monitor | CVE-2020-11910No exploit | The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium5.3 | — | 10.9% | Jun 17, 2020 |
22Monitor | CVE-2020-11912No exploit | The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium5.3 | — | 4.5% | Jun 17, 2020 |
22Monitor | CVE-2020-11909No exploit | The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.treck · tcp\/ip · CWE-191 | Medium5.3 | — | 3.6% | Jun 17, 2020 |
22Monitor | CVE-2020-11913No exploit | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium5.3 | — | 3.3% | Jun 17, 2020 |
22Monitor | CVE-2020-11911No exploit | The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.treck · tcp\/ip · CWE-732 | Medium5.3 | — | 3.1% | Jun 17, 2020 |
22Monitor | CVE-2020-27336No exploit | An issue was discovered in Treck IPv6 before 6.0.1.68.treck · ipv6 · CWE-20 | Medium5.3 | — | 1.7% | Dec 22, 2020 |
18Monitor | CVE-2020-11908No exploit | The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.treck · tcp\/ip | Medium4.3 | — | 1.9% | Jun 17, 2020 |
17Monitor | CVE-2020-11914No exploit | The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium4.3 | — | 1.7% | Jun 17, 2020 |
- CVE-2020-1189957Plan
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
MediumCVSS 5.4KEVWeaponizedEPSS 19%treck · tcp\/ipJun 17, 2020
- CVE-2020-1189651Plan
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.
CriticalCVSS 10.0Proof of conceptEPSS 37%treck · tcp\/ipJun 17, 2020
- CVE-2020-1189743Plan
The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.
CriticalCVSS 10.0No exploitEPSS 9%treck · tcp\/ipJun 17, 2020
- CVE-2020-1190142Plan
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
CriticalCVSS 9.0No exploitEPSS 21%treck · tcp\/ipJun 17, 2020
- CVE-2020-1189842Plan
The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers
CriticalCVSS 9.1Proof of conceptEPSS 19%treck · tcp\/ipJun 17, 2020
- CVE-2020-2506640Plan
A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/
CriticalCVSS 9.8No exploitEPSS 3%treck · tcp\/ipDec 22, 2020
- CVE-2020-1190036Monitor
The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.
HighCVSS 8.2No exploitEPSS 13%treck · tcp\/ipJun 17, 2020
- CVE-2020-1190232Monitor
The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.
HighCVSS 7.3No exploitEPSS 9%treck · tcp\/ipJun 17, 2020
- CVE-2020-1013630Monitor
IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network traffic
MediumCVSS 5.3Proof of conceptEPSS 29%cisco · nx-osJun 2, 2020
- CVE-2020-1190430Monitor
The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.
HighCVSS 7.3No exploitEPSS 3%treck · tcp\/ipJun 17, 2020
- CVE-2020-2733729Monitor
An issue was discovered in Treck IPv6 before 6.0.1.68.
HighCVSS 7.3No exploitEPSS 1%treck · ipv6Dec 22, 2020
- CVE-2020-2733828Monitor
An issue was discovered in Treck IPv6 before 6.0.1.68.
HighCVSS 7.1No exploitEPSS 1%treck · ipv6Dec 22, 2020
- CVE-2020-1190327Monitor
The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.
MediumCVSS 6.5No exploitEPSS 2%treck · tcp\/ipJun 17, 2020
- CVE-2020-1190527Monitor
The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.
MediumCVSS 6.5No exploitEPSS 2%treck · tcp\/ipJun 17, 2020
- CVE-2020-1190726Monitor
The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.
MediumCVSS 6.3No exploitEPSS 2%treck · tcp\/ipJun 17, 2020
- CVE-2020-1190626Monitor
The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.
MediumCVSS 6.3No exploitEPSS 2%treck · tcp\/ipJun 17, 2020
- CVE-2020-1191024Monitor
The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.
MediumCVSS 5.3No exploitEPSS 11%treck · tcp\/ipJun 17, 2020
- CVE-2020-1191222Monitor
The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.
MediumCVSS 5.3No exploitEPSS 5%treck · tcp\/ipJun 17, 2020
- CVE-2020-1190922Monitor
The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.
MediumCVSS 5.3No exploitEPSS 4%treck · tcp\/ipJun 17, 2020
- CVE-2020-1191322Monitor
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
MediumCVSS 5.3No exploitEPSS 3%treck · tcp\/ipJun 17, 2020
- CVE-2020-1191122Monitor
The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.
MediumCVSS 5.3No exploitEPSS 3%treck · tcp\/ipJun 17, 2020
- CVE-2020-2733622Monitor
An issue was discovered in Treck IPv6 before 6.0.1.68.
MediumCVSS 5.3No exploitEPSS 2%treck · ipv6Dec 22, 2020
- CVE-2020-1190818Monitor
The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.
MediumCVSS 4.3No exploitEPSS 2%treck · tcp\/ipJun 17, 2020
- CVE-2020-1191417Monitor
The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.
MediumCVSS 4.3No exploitEPSS 2%treck · tcp\/ipJun 17, 2020