Description
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a packet sent by an unauthenticated remote attacker could result in an out-of-bounds read of up to three bytes via network access.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://treck.com/vulnerability-response-information/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210201-0003/
Scores
CVSS v3
3.7
EPSS
0.0027
EPSS Percentile
50.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-125
CWE-20
Status
published
Products (1)
treck/ipv6
< 6.0.1.68
Published
Dec 22, 2020
Tracked Since
Feb 18, 2026