Search

Security Information: Treck TCP/IP stack vulnerabilities

Canon Medical Systems Security Advisory

Overview
It was announced that there are multiple security vulnerabilities in Treck TCP/IP stack. Treck TCP/IP stack is a low-level TCP/IP software library. There is a possibility that an attacker who successfully exploited these vulnerabilities could perform remote code execution or exposure of sensitive information.

Vulnerability Overview

CVE IDCVSSv3DescriptionImpactExploitability Assessment
CVE-2020-1189610The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.Remote Code ExecutionN/A
CVE-2020-1189710The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.Out-of-Bounds WriteN/A
CVE-2020-118989.1The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.Exposure of Sensitive InformationN/A
CVE-2020-118995.4The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.Out-of-bounds Read, Denial of Servi/ce
N/A
CVE-2020-119008.2The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.Use After FreeNA
CVE-2020-119019The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.Remote Code ExecutionN/A
CVE-2020-119027.3The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.Out-of-bounds ReadN/A
CVE-2020-119035.3The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.Exposure of Sensitive InformationN/A
CVE-2020-119045.6The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.Out-of-Bounds WriteN/A
CVE-2020-119055.3The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.Exposure of Sensitive InformationN/A
CVE-2020-119065The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.Integer UnderflowN/A
CVE-2020-119075The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.Integer UnderflowN/A
CVE-2020-119083.1The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.Exposure of Sensitive InformationN/A
CVE-2020-119093.7The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.Integer UnderflowN/A
CVE-2020-119103.7The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.Out-of-bounds ReadN/A
CVE-2020-119113.7The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.Incorrect Permission Assignment for Critical ResourceN/A
CVE-2020-119123.7The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.Out-of-bounds ReadN/A
CVE-2020-119133.7The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.Out-of-bounds ReadN/A
CVE-2020-119143.1The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.Out-of-bounds ReadN/A



Affected products
Canon Medical Systems Corporation is not using Treck TCP/IP stack directly in its products. Canon Medical Systems Corporation is currently investigating whether there is any impact to third party components used in its products. If any impact is found, it will be informed to customer immediately.