CVE-2020-11898
CRITICALTreck TCP/IP < 6.0.1.66 - Information Disclosure via IPv4/ICMPv4 Length Parameter Inconsistency
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-11898. PoCs published by Ransc0rp1on.
AI-analyzed exploit summary This repository contains a Python-based scanner for detecting CVE-2020-11898 (Ripple20), a vulnerability in the Treck TCP/IP stack. The tool sends crafted fragmented IP-in-IP packets and analyzes ICMP responses to determine if the target is vulnerable to heap data leakage.
Description
The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.
Exploits (1)
This repository contains a Python-based scanner for detecting CVE-2020-11898 (Ripple20), a vulnerability in the Treck TCP/IP stack. The tool sends crafted fragmented IP-in-IP packets and analyzes ICMP responses to determine if the target is vulnerable to heap data leakage.
References (10)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H