VYPR
Unrated severityNVD Advisory· Published Jun 17, 2020· Updated Aug 4, 2024

CVE-2020-11901

CVE-2020-11901

Description

The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A single malformed DNS response can achieve remote code execution on devices using the Treck TCP/IP stack before 6.0.1.66.

Vulnerability

CVE-2020-11901 is a remote code execution vulnerability in the Treck TCP/IP stack versions prior to 6.0.1.66 [1]. The bug is triggered by processing a single invalid DNS response, which causes a memory corruption that can be exploited for arbitrary code execution [1]. The vulnerability resides in the DNS response parsing logic of the Treck stack and is reachable when the affected device performs DNS resolution [1].

Exploitation

An unauthenticated, remote attacker can send a specially crafted DNS response to a vulnerable device that performs DNS lookups [1]. No prior authentication or special network position is required, as the attacker only needs to deliver a malicious DNS reply to the target [1]. The exploitation step is a single malformed DNS response [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code on the target device with the privileges of the Treck stack process [1]. This can lead to full compromise of the device, including data disclosure, denial of service, or further lateral movement depending on the device's role in the network [1].

Mitigation

Treck has released version 6.0.1.67 (and later) of the IP stack to address this vulnerability [1]. Vendors that use the Treck stack, such as Cisco and Dell, have issued advisories and patches for affected products [2][3][4]. Users should update to the latest patched version provided by their device vendor or apply network-level mitigations such as deep packet inspection to block malformed DNS responses [1][2][4].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.