CVE-2020-25767

HIGH

Hcc-embedded Nichestack Ipv4 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does not check whether a domain name compression pointer is pointing within the bounds of the packet (e.g., forward compression pointer jumps are allowed), which leads to an Out-of-bounds Read, and a Denial-of-Service as a consequence.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/608209

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
hcc-embedded/nichestack_ipv4 4.1
Published Aug 18, 2021
Tracked Since Feb 18, 2026