<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:06:28.593756+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-01902</id>
    <title>bdu:2022-01902</title>
    <updated>2026-10-02T11:06:28.606819+00:00</updated>
    <content>bdu:2022-01902</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-01902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-375</id>
    <title>certfr-2020-avi-375 — Le 16 juin 2020, des chercheurs ont annoncé la découverte de dix-neuf
vulnérabilités dans l'implémentation de la pile T…</title>
    <updated>2026-10-02T11:06:28.606858+00:00</updated>
    <content>certfr-2020-avi-375</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-treck-ip-stack-jybq5gyc</id>
    <title>cisco-sa-treck-ip-stack-JyBQ5GyC — Multiple Vulnerabilities in Treck IP Stack Affecting Cisco Products: June 2020</title>
    <updated>2026-10-02T11:06:28.606888+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A set of previously unknown vulnerabilities on the Treck IP stack implementation were disclosed on June 16, 2020. The vulnerabilities are collectively known as Ripple20. Exploitation of these vulnerabilities could result in remote code execution, denial of service (DoS), or information disclosure, depending on the specific vulnerability.

This advisory will be updated as additional information becomes available.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC"]</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-treck-ip-stack-jybq5gyc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-34240</id>
    <title>cnvd-2020-34240</title>
    <updated>2026-10-02T11:06:28.606925+00:00</updated>
    <content>cnvd-2020-34240</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-34240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-40948</id>
    <title>EUVD-2026-40948</title>
    <updated>2026-10-02T11:06:28.606937+00:00</updated>
    <content>EUVD-2026-40948</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-40948"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11912</id>
    <title>fkie_cve-2020-11912</title>
    <updated>2026-10-02T11:06:28.606947+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-11912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w9wg-858m-29fc</id>
    <title>GHSA-w9wg-858m-29fc</title>
    <updated>2026-10-02T11:06:28.606966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w9wg-858m-29fc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-11912</id>
    <title>gsd-2020-11912</title>
    <updated>2026-10-02T11:06:28.606979+00:00</updated>
    <content>gsd-2020-11912</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-11912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-168-01</id>
    <title>ICSA-20-168-01 — Treck TCP/IP (Update I)</title>
    <updated>2026-10-02T11:06:28.606988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper handling of length parameter inconsistency in IPv4/UDP component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution. Improper handling of length parameter inconsistency in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in possible out-of-bounds write. Improper handling of length parameter inconsistency in IPv4/ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in out-of-bounds read. Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read and a possible denial of service. Possible double free in IPv4 tunneling component when handling a packet sent by a network attacker. This vulnerability may result in use after free. Improper input validation in DNS resolver component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution. Improper input validation in IPv6 over IPv4 tunneling component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read. Possible out-of-bounds read in DHCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information. Possible integer overflow or wraparound in me…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-168-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2020-174-01</id>
    <title>SEVD-2020-174-01 — APC by Schneider Electric Network Management Cards (NMC) and NMC Embedded Devices</title>
    <updated>2026-10-02T11:06:28.607030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric became aware of multiple vulnerabilities affecting Treck Inc.'s embedded TCP/IP 
stack, collectively known as Ripple20, which Treck publicly disclosed on June 16, 2020. Schneider 
Electric is also aware of a proof of concept published by JSOF that demonstrates how one of the 
Treck vulnerabilities, CVE-2020-11901, can be exploited to affect a Schneider Electric APC SmartUPS device using certain Network Management Card firmware versions. 
On October 12, 2020, Schneider Electric received additional information and analysis from JSOF
related to CVE-2020-11901’s impact on APC by Schneider Electric Network Management Cards and 
NMC embedded devices. This new analysis indicates that the information we originally received was 
incomplete. Therefore our original remediations are only partially effective for CVE-2020-11901. We 
are expediting updated remediations, which will be made available as soon as possible. In the 
meantime, customers should immediately apply the mitigations included in Remediation &amp; Mitigations
section of this document.
June 2021 Update: Added remediations for Uninterruptible Power Supply (UPS), Rack Power 
Distribution Units (rPDU), Battery Management, Rack Automatic Transfer Switch (ATS), Rack Air 
Removal Unit (RARU) using NMC1, as well as all other remaining NMC1 applications.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2020-174-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-024</id>
    <title>VDE-2020-024 — Miele: Treck TCP/IP Vulnerabilities (Ripple20) affecting Communication Module XKM3000 L MED</title>
    <updated>2026-10-02T11:06:28.607064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module.</p>
<p>The communication module is separate from the actual device control and uses a chipset from Digi International.</p>
<p>The TCP / IP stack required for networking is implemented in this chipset with the help of a 3rd party library from Treck. External security researchers have identified several security holes in this library called Ripple20. The most critical vulnerability allows an external attacker to execute arbitrary code on the chip and thus also on the communication module.</p>
<p>The above named communication module can be integrated into the following laboratory washers, thermal disinfectors and washer- disinfectors:</p>
<p>- PG 8581
- PG 8582
- PG 8583
- PG 8583 CD
- PG 8591
- PG 8582 CD
- PG 8592
- PG 8593
- PG 8562</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-028</id>
    <title>VDE-2021-028 — Pepperl+Fuchs: Multiple VDM100-Distance Ethernet-IP sensors with multiple vulnerabilities</title>
    <updated>2026-10-02T11:06:28.607090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the utilized component TRECK TCP/IP Stack by Digi International Inc.</p>
<p>For more information see advisory by Digi International Inc.:
Digi International Security Notice - TRECK TCP/IP Stack "RIPPLE20" VU#257161 ICS-VU-035787 | Digi International</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0683</id>
    <title>WID-SEC-W-2023-0683 — Treck TCP/IP-Stack: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:06:28.607112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Produkten, die die Treck TCP/IP-Stack-Bibliothek verwenden, ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0683"/>
  </entry>
</feed>
