<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:07:45 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-02193</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-02193</link>
      <description>bdu:2022-02193</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-02193</guid>
    </item>
    <item>
      <title>certfr-2020-avi-375 — Le 16 juin 2020, des chercheurs ont annoncé la découverte de dix-neuf
vulnérabilités dans l'implémentation de la pile T…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-375</link>
      <description>certfr-2020-avi-375</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-375</guid>
    </item>
    <item>
      <title>cisco-sa-treck-ip-stack-JyBQ5GyC — Multiple Vulnerabilities in Treck IP Stack Affecting Cisco Products: June 2020</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-treck-ip-stack-jybq5gyc</link>
      <description>&lt;p&gt;A set of previously unknown vulnerabilities on the Treck IP stack implementation were disclosed on June 16, 2020. The vulnerabilities are collectively known as Ripple20. Exploitation of these vulnerabilities could result in remote code execution, denial of service (DoS), or information disclosure, depending on the specific vulnerability.&#13;
&#13;
This advisory will be updated as additional information becomes available.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC&amp;#34;]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A set of previously unknown vulnerabilities on the Treck IP stack implementation were disclosed on June 16, 2020. The vulnerabilities are collectively known as Ripple20. Exploitation of these vulnerabilities could result in remote code execution, denial of service (DoS), or information disclosure, depending on the specific vulnerability.&#13;
&#13;
This advisory will be updated as additional information becomes available.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC&amp;#34;]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-treck-ip-stack-jybq5gyc</guid>
    </item>
    <item>
      <title>cnvd-2020-34238</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-34238</link>
      <description>cnvd-2020-34238</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-34238</guid>
    </item>
    <item>
      <title>EUVD-2026-40895</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-40895</link>
      <description>EUVD-2026-40895</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-40895</guid>
    </item>
    <item>
      <title>fkie_cve-2020-11914</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11914</link>
      <description>&lt;p&gt;The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-11914</guid>
    </item>
    <item>
      <title>GHSA-7rj5-xw53-7j3v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7rj5-xw53-7j3v</link>
      <description>&lt;p&gt;The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7rj5-xw53-7j3v</guid>
    </item>
    <item>
      <title>gsd-2020-11914</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-11914</link>
      <description>gsd-2020-11914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-11914</guid>
    </item>
    <item>
      <title>ICSA-20-168-01 — Treck TCP/IP (Update I)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-20-168-01</link>
      <description>&lt;p&gt;Improper handling of length parameter inconsistency in IPv4/UDP component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution. Improper handling of length parameter inconsistency in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in possible out-of-bounds write. Improper handling of length parameter inconsistency in IPv4/ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in out-of-bounds read. Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read and a possible denial of service. Possible double free in IPv4 tunneling component when handling a packet sent by a network attacker. This vulnerability may result in use after free. Improper input validation in DNS resolver component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution. Improper input validation in IPv6 over IPv4 tunneling component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read. Possible out-of-bounds read in DHCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information. Possible integer overflow or wraparound in me…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper handling of length parameter inconsistency in IPv4/UDP component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution. Improper handling of length parameter inconsistency in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in possible out-of-bounds write. Improper handling of length parameter inconsistency in IPv4/ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in out-of-bounds read. Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read and a possible denial of service. Possible double free in IPv4 tunneling component when handling a packet sent by a network attacker. This vulnerability may result in use after free. Improper input validation in DNS resolver component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution. Improper input validation in IPv6 over IPv4 tunneling component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read. Possible out-of-bounds read in DHCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information. Possible integer overflow or wraparound in me…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-20-168-01</guid>
    </item>
    <item>
      <title>SEVD-2020-174-01 — APC by Schneider Electric Network Management Cards (NMC) and NMC Embedded Devices</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-174-01</link>
      <description>&lt;p&gt;Schneider Electric became aware of multiple vulnerabilities affecting Treck Inc.&amp;#39;s embedded TCP/IP &#13;
stack, collectively known as Ripple20, which Treck publicly disclosed on June 16, 2020. Schneider &#13;
Electric is also aware of a proof of concept published by JSOF that demonstrates how one of the &#13;
Treck vulnerabilities, CVE-2020-11901, can be exploited to affect a Schneider Electric APC SmartUPS device using certain Network Management Card firmware versions. &#13;
On October 12, 2020, Schneider Electric received additional information and analysis from JSOF&#13;
related to CVE-2020-11901’s impact on APC by Schneider Electric Network Management Cards and &#13;
NMC embedded devices. This new analysis indicates that the information we originally received was &#13;
incomplete. Therefore our original remediations are only partially effective for CVE-2020-11901. We &#13;
are expediting updated remediations, which will be made available as soon as possible. In the &#13;
meantime, customers should immediately apply the mitigations included in Remediation &amp;amp; Mitigations&#13;
section of this document.&#13;
June 2021 Update: Added remediations for Uninterruptible Power Supply (UPS), Rack Power &#13;
Distribution Units (rPDU), Battery Management, Rack Automatic Transfer Switch (ATS), Rack Air &#13;
Removal Unit (RARU) using NMC1, as well as all other remaining NMC1 applications.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric became aware of multiple vulnerabilities affecting Treck Inc.&amp;#39;s embedded TCP/IP &#13;
stack, collectively known as Ripple20, which Treck publicly disclosed on June 16, 2020. Schneider &#13;
Electric is also aware of a proof of concept published by JSOF that demonstrates how one of the &#13;
Treck vulnerabilities, CVE-2020-11901, can be exploited to affect a Schneider Electric APC SmartUPS device using certain Network Management Card firmware versions. &#13;
On October 12, 2020, Schneider Electric received additional information and analysis from JSOF&#13;
related to CVE-2020-11901’s impact on APC by Schneider Electric Network Management Cards and &#13;
NMC embedded devices. This new analysis indicates that the information we originally received was &#13;
incomplete. Therefore our original remediations are only partially effective for CVE-2020-11901. We &#13;
are expediting updated remediations, which will be made available as soon as possible. In the &#13;
meantime, customers should immediately apply the mitigations included in Remediation &amp;amp; Mitigations&#13;
section of this document.&#13;
June 2021 Update: Added remediations for Uninterruptible Power Supply (UPS), Rack Power &#13;
Distribution Units (rPDU), Battery Management, Rack Automatic Transfer Switch (ATS), Rack Air &#13;
Removal Unit (RARU) using NMC1, as well as all other remaining NMC1 applications.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-174-01</guid>
    </item>
    <item>
      <title>VDE-2020-024 — Miele: Treck TCP/IP Vulnerabilities (Ripple20) affecting Communication Module XKM3000 L MED</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-024</link>
      <description>&lt;p&gt;For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module.&lt;/p&gt;
&lt;p&gt;The communication module is separate from the actual device control and uses a chipset from Digi International.&lt;/p&gt;
&lt;p&gt;The TCP / IP stack required for networking is implemented in this chipset with the help of a 3rd party library from Treck. External security researchers have identified several security holes in this library called Ripple20. The most critical vulnerability allows an external attacker to execute arbitrary code on the chip and thus also on the communication module.&lt;/p&gt;
&lt;p&gt;The above named communication module can be integrated into the following laboratory washers, thermal disinfectors and washer- disinfectors:&lt;/p&gt;
&lt;p&gt;- PG 8581
- PG 8582
- PG 8583
- PG 8583 CD
- PG 8591
- PG 8582 CD
- PG 8592
- PG 8593
- PG 8562&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module.&lt;/p&gt;
&lt;p&gt;The communication module is separate from the actual device control and uses a chipset from Digi International.&lt;/p&gt;
&lt;p&gt;The TCP / IP stack required for networking is implemented in this chipset with the help of a 3rd party library from Treck. External security researchers have identified several security holes in this library called Ripple20. The most critical vulnerability allows an external attacker to execute arbitrary code on the chip and thus also on the communication module.&lt;/p&gt;
&lt;p&gt;The above named communication module can be integrated into the following laboratory washers, thermal disinfectors and washer- disinfectors:&lt;/p&gt;
&lt;p&gt;- PG 8581
- PG 8582
- PG 8583
- PG 8583 CD
- PG 8591
- PG 8582 CD
- PG 8592
- PG 8593
- PG 8562&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-024</guid>
    </item>
    <item>
      <title>VDE-2021-028 — Pepperl+Fuchs: Multiple VDM100-Distance Ethernet-IP sensors with multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-028</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component TRECK TCP/IP Stack by Digi International Inc.&lt;/p&gt;
&lt;p&gt;For more information see advisory by Digi International Inc.:
Digi International Security Notice - TRECK TCP/IP Stack &amp;#34;RIPPLE20&amp;#34; VU#257161 ICS-VU-035787 | Digi International&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component TRECK TCP/IP Stack by Digi International Inc.&lt;/p&gt;
&lt;p&gt;For more information see advisory by Digi International Inc.:
Digi International Security Notice - TRECK TCP/IP Stack &amp;#34;RIPPLE20&amp;#34; VU#257161 ICS-VU-035787 | Digi International&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-028</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0683 — Treck TCP/IP-Stack: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0683</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Produkten, die die Treck TCP/IP-Stack-Bibliothek verwenden, ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Produkten, die die Treck TCP/IP-Stack-Bibliothek verwenden, ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0683</guid>
    </item>
  </channel>
</rss>
