ICSA-20-353-01
·
Published 2021-01-26
·
View on CISA ICS-CERT ↗
Treck TCP/IP Stack (Update A)
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of this vulnerability may allow remote code execution and a denial-of-service condition.
Remediations
- Treck recommends users apply the latest version of the affected products (Treck TCP/IP 6.0.1.68 or later versions). To obtain patches, email [email protected]
- Treck recommends users who cannot apply the latest patches to implement firewall rules to filter out packets that contain a negative content length in the HTTP header.
- For more detailed information on the vulnerabilities and the mitigating controls, please see the Treck advisory.
Affected Vendors
Treck Inc
Affected Products (3)
Treck Inc
·
TCP/IP stack IPv6
<= 6.0.1.67
Treck Inc
·
TCP/IP stack HTTP Server
<= 6.0.1.67
Treck Inc
·
TCP/IP stack DHCPv6
<= 6.0.1.67
Affected Sectors
Critical Manufacturing, Information Technology, Healthcare and Public Health, Transportation Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more