Vulnerability Description
A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Treck | Tcp\/Ip | < 6.0.1.68 |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20210201-0003/Third Party Advisory
- https://treck.com/vulnerability-response-information/Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210201-0003/Third Party Advisory
- https://treck.com/vulnerability-response-information/Vendor Advisory
FAQ
What is CVE-2020-25066?
CVE-2020-25066 is a vulnerability with a CVSS score of 10.0 (CRITICAL). A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.
How severe is CVE-2020-25066?
CVE-2020-25066 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-25066?
Check the references section above for vendor advisories and patch information. Affected products include: Treck Tcp\/Ip.