CVE-2020-11902
Description
The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read vulnerability in Treck TCP/IP stack's IPv6OverIPv4 tunneling can cause information disclosure or denial of service.
Vulnerability
CVE-2020-11902 is an out-of-bounds read vulnerability in the IPv6OverIPv4 tunneling component of the Treck TCP/IP stack, affecting versions before 6.0.1.66 [1]. The bug exists in the code that handles encapsulation of IPv6 packets within IPv4 tunnels, and can be triggered by processing a specially crafted network packet. The Treck stack is widely used in embedded systems, including industrial control and medical devices [1].
Exploitation
A remote, unauthenticated attacker can exploit this vulnerability by sending a custom-crafted network packet to a device running an affected version of the Treck stack [1][2]. No user interaction is required; the attack is launched over the network and can target the IPv6OverIPv4 tunneling functionality. The out-of-bounds read occurs when the stack incorrectly parses tunneled packet headers [1].
Impact
Successful exploitation allows the attacker to read beyond the bounds of the intended buffer, potentially leading to information disclosure (exposure of sensitive memory contents) or denial of service (crash or hang of the device) [1][2]. The impact depends on the system's build and runtime options, but the vulnerability is remotely exploitable without authentication [1][2].
Mitigation
Treck has released version 6.0.1.67 (or later) which fixes this vulnerability [1][2]. Users should update their Treck IP stack to the latest stable release. Downstream vendors integrating the Treck stack (such as Dell and Cisco) have published advisories and patches for their affected products [3][4]. As a workaround, organizations can block anomalous IP traffic using deep packet inspection or firewall rules that drop malformed packets [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Treck/TCP/IP stackdescription
- Range: <6.0.1.66
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyCmitrevendor-advisoryx_refsource_CISCO
- www.kb.cert.org/vuls/id/257161mitrethird-party-advisoryx_refsource_CERT-VN
- www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txtmitrex_refsource_CONFIRM
- jsof-tech.com/vulnerability-disclosure-policy/mitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20200625-0006/mitrex_refsource_CONFIRM
- www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilitiesmitrex_refsource_MISC
- www.jsof-tech.com/ripple20/mitrex_refsource_MISC
- www.kb.cert.org/vuls/id/257161/mitrex_refsource_MISC
- www.treck.commitrex_refsource_MISC
News mentions
0No linked articles in our index yet.