CVE-2020-11907
Es existieren mehrere Schwachstellen in Produkten, die eine TCP/IP-Stack-Bibliothek des Herstellers Treck verwenden. Die Schwachstellen werden gesammelt als "Ripple20" bezeichnet und betreffen Produkte aus verschiedensten Sektoren. Die Schwachstellen bestehen aufgrund einer fehlerhaften Behandlung von Inkonsistenzen bei Längenparametern, einer unsachgemäßen Eingabevalidierung, Double Free-Fehlern, Out-of-Bounds-Lese-Fehlern, Integer-Überlaufen oder Wraparounds, einer unsachgemäßen Null-Terminierung, sowie einer unsachgemäßen Zugriffskontrolle. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herzustellen.
EPSS 1.09% · 78.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| HPE | HPE Integrated Lights-Out 3 | |
| Aruba | Aruba Switch | |
| HP | HP LaserJet | |
| Xerox | Xerox FreeFlow Print Server | |
| Dell | Dell Computer | |
| Intel | Intel BIOS | |
| HPE | HPE Integrated Lights-Out 5 | |
| HPE | HPE ProLiant | |
| Eaton | Eaton UPS | |
| Aruba | Aruba ArubaOS | |
| Cisco | Cisco Router | |
| Intel | Intel Server Firmware | |
| PaloAlto Networks | PaloAlto Networks PAN-OS |
Exploit Intelligence
- https://www.jsof-tech.com/ripple20/ (nist-nvd)
- https://www.kb.cert.org/vuls/id/257161/ (circl)
- https://www.treck.com (circl)
- https://jsof-tech.com/vulnerability-disclosure-policy/ (circl)
- VU#257161 (circl)
- 20200617 Multiple Vulnerabilities in Treck IP Stack Affecting Cisco Products: June 2020 (circl)
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt (circl)
- https://security.netapp.com/advisory/ntap-20200625-0006/ (circl)
- https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04012en_us (circl)
- https://www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilities (circl)
Timeline
- Jun 16, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2020/wid-sec-w-2023-0683.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0683 advisory
- https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/ETN-SB-2020-1008.pdf advisory
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04103en_us advisory
- https://www.jsof-tech.com/ripple20/ advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html advisory
- https://support.hp.com/emea_africa-en/document/c06640149 advisory
- https://www.se.com/ww/en/download/document/SESB-2020-168-01/ advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-168-01 advisory
- https://www.kb.cert.org/vuls/id/257161 advisory
- https://security.business.xerox.com/wp-content/uploads/2020/06/cert_Security_Mini_Bulletin_XRX20J_for_B2XX.pdf advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC advisory
- https://www.dell.com/support/article/sln321836/dell-response-to-the-ripple20-vulnerabilities?lang=en advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txt advisory
- https://www.dell.com/support/article/sln321835/dsa-2020-150-dell-client-platform-security-update-for-treck-tcp-ip-stack-vulnerabilities-in-teradici-firmware-and-remote-workstation-cards?lang=en advisory
- https://security.paloaltonetworks.com/PAN-SA-2020-0007 advisory
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04012en_us advisory
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04021en_us advisory
- https://www.dell.com/support/kbdoc/de-de/000125440/dsa-2020-206-dell-client-platform-security-update-for-treck-tcp-ip-stack-vulnerabilities-in-teradici-firmware-and-remote-workstation-cards advisory