CVE-2020-11900
https://notcve.org/view.php?id=CVE-2020-11900
The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free. La pila Treck TCP/IP versiones anteriores a 6.0.1.41, presenta una Doble Liberación al hacer un túnel IPv4 • http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt https://jsof-tech.com/vulnerability-disclosure-policy https://security.netapp.com/advisory/ntap-20200625-0006 https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04012en_us https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities https://www.intel.com/content/www/us/en • CWE-415: Double Free •
CVE-2020-11899 – Treck TCP/IP stack Out-of-Bounds Read Vulnerability
https://notcve.org/view.php?id=CVE-2020-11899
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. La pila de Treck TCP/IP versiones anteriores a 6.0.1.66, presenta una Lectura Fuera de Límites The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. • http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt https://cwe.mitre.org/data/definitions/125.html https://jsof-tech.com/vulnerability-disclosure-policy https://security.netapp.com/advisory/ntap-20200625-0006 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-0 • CWE-125: Out-of-bounds Read •
CVE-2020-11898
https://notcve.org/view.php?id=CVE-2020-11898
The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak. La pila Treck TCP/IP versiones anteriores a 6.0.1.66, maneja inapropiadamente una Inconsistencia del Parámetro de Longitud de IPv4/ICMPv4, lo que podría permitir a atacantes remotos desencadenar una filtración de información • http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt https://jsof-tech.com/vulnerability-disclosure-policy https://security.netapp.com/advisory/ntap-20200625-0006 https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04012en_us https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities https://www.jsof-tech.com/ripple20 https: • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2020-11897
https://notcve.org/view.php?id=CVE-2020-11897
The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets. La pila Treck TCP/IP versiones anteriores a 5.0.1.35, presenta una Escritura Fuera de Límites por medio de múltiples paquetes IPv6 malformados • http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt https://jsof-tech.com/vulnerability-disclosure-policy https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities https://www.jsof-tech.com/ripple20 https://www.kb.cert.org/vuls/id/257161 https://www.treck.com • CWE-787: Out-of-bounds Write •
CVE-2020-11896
https://notcve.org/view.php?id=CVE-2020-11896
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling. La pila Treck TCP/IP versiones anteriores a 6.0.1.66, permite una Ejecución de Código Remota, relacionada con el túnel IPv4 • http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt https://cert-portal.siemens.com/productcert/pdf/ssa-631949.pdf https://jsof-tech.com/vulnerability-disclosure-policy https://security.netapp.com/advisory/ntap-20200625-0006 https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04012en_us https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-r • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-787: Out-of-bounds Write •