CVE-2020-11899

MEDIUM(5.4)KEVElevated Risk

Treck TCP/IP stack Out-of-Bounds Read Vulnerability

Description

CVE-2020-11899 is a medium-severity out-of-bounds read vulnerability affecting Treck TCP/IP stack IPv6. The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 33.25% (96.8th percentile), this vulnerability has a notable probability of exploitation.

KEV Information

Vendor
Treck TCP/IP stack
Product
IPv6
Date Added
March 3, 2022
Due Date
March 17, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LOpen in Calculator
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
2.5

CWEs

Affected Products

VendorProductVersion
trecktcp\/ip< 6.0.1.66
dellwyse 5050 all-in-one firmware-
dellwyse 7030 firmware-
dellwyse 5030 firmware-

Multiple CVSS Assessments

Source: [email protected](Primary)
5.4
MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
5.4
MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

References

Weakness Type

CWE-125: Out-of-bounds Read

Out-of-bounds Read is a vulnerability that occurs when software reads data from a memory location outside the intended boundaries of a buffer. This happens when array indices, pointer arithmetic, or buffer offsets are calculated incorrectly or not properly validated against buffer limits.

Learn more: CWE-125 — Out-of-bounds Read

Impact Analysis

CVE-2020-11899 carries a CVSS 3.1 score of 5.4 (MEDIUM), indicating a moderate-severity threat. The vulnerability is exploitable from an adjacent network with low attack complexity and requires no authentication. Successful exploitation can allow limited unauthorized data modification, and cause partial service degradation. Organizations running affected IPv6 deployments face significant operational risk if this vulnerability remains unpatched.

Exploit Maturity

CVE-2020-11899 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 33.25% (96.8th percentile) indicates a significant probability of exploitation. Public exploit code is available, which lowers the barrier for attackers and increases the urgency of remediation. Federal agencies were required to remediate this vulnerability by 2022-03-17 per CISA's binding operational directive.

Remediation

  1. Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions.
  2. Verify that all instances of affected products (treck tcp/ip < 6.0.1.66; dell wyse 5050 all-in-one firmware -; dell wyse 7030 firmware -) have been updated to patched versions.
  3. If immediate patching is not possible, restrict local access to affected systems and enforce principle of least privilege.
  4. Monitor systems for indicators of compromise, including unusual process activity, unexpected network connections, and unauthorized configuration changes.
  5. Review security logs and conduct threat hunting to determine if the vulnerability was exploited prior to patching.

Technical Details

CVE-2020-11899 affects Treck TCP/IP stack IPv6. The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. The attack vector requires adjacent network access, meaning the attacker must be on the same network segment as the target. The CVSS score of 5.4 reflects a moderate vulnerability, but its inclusion in the KEV catalog confirms real-world exploitation risk.

Frequently Asked Questions

Is CVE-2020-11899 being actively exploited?

Yes. CVE-2020-11899 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 33.25% (96.8th percentile) further indicates a significant exploitation probability.

What products are affected by CVE-2020-11899?

CVE-2020-11899 affects Treck TCP/IP stack IPv6. Specifically affected products include: treck tcp/ip (< 6.0.1.66), dell wyse 5050 all-in-one firmware (-), dell wyse 7030 firmware (-), dell wyse 5030 firmware (-).

How do I fix CVE-2020-11899?

Apply updates per vendor instructions. Ensure all affected systems are updated to the latest patched versions. If patching is not immediately possible, implement network-level mitigations to limit exposure.

How severe is CVE-2020-11899?

CVE-2020-11899 has a CVSS 3.1 score of 5.4 (MEDIUM). While rated as medium severity, its presence in the KEV catalog confirms it is being actively exploited and should be remediated promptly.

CVSS Score

5.4
MEDIUM(5.4)

EPSS Score

EPSS Score18.56%
EPSS Percentile97.0%

Dates

PublishedJune 17, 2020
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.