Critical Vulnerabilities in Treck TCP/IP stack software
The JSOF research lab has discovered a series of zero-day vulnerabilities in a widely used low-level TCP/IP software library developed by Treck, Inc. The 19 vulnerabilities, given the name Ripple20, affect hundreds of millions of devices and include multiple remote code execution vulnerabilities. These vulnerabilities affect Treck TCP/IP stack implementations for embedded systems.
The Treck TCP/IP stack is affected including:
Successful exploitation of these vulnerabilities may allow remote code execution or exposure of sensitive information.
Treck recommends users apply the latest version of the affected products (Treck TCP/IP 126.96.36.199 or later versions). To obtain patches, email firstname.lastname@example.org.
17 Sep 2020 - Security Advisories & Alerts