← Back to home
ICSA-20-353-01  ·  Published 2021-01-26  ·  View on CISA ICS-CERT ↗

Treck TCP/IP Stack (Update A)

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability may allow remote code execution and a denial-of-service condition.

Remediations

  • Treck recommends users apply the latest version of the affected products (Treck TCP/IP 6.0.1.68 or later versions). To obtain patches, email [email protected]
  • Treck recommends users who cannot apply the latest patches to implement firewall rules to filter out packets that contain a negative content length in the HTTP header.
  • For more detailed information on the vulnerabilities and the mitigating controls, please see the Treck advisory.

Affected Vendors

Treck Inc

Affected Products (3)

Treck Inc · TCP/IP stack IPv6 <= 6.0.1.67
Treck Inc · TCP/IP stack HTTP Server <= 6.0.1.67
Treck Inc · TCP/IP stack DHCPv6 <= 6.0.1.67

Affected Sectors

Critical Manufacturing, Information Technology, Healthcare and Public Health, Transportation Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more