{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":" Digi International Inc.","summary":"reporting."}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-US","notes":[{"category":"summary","text":"Critical vulnerabilities have been discovered in the utilized component TRECK TCP/IP Stack by Digi International Inc.\n\nFor more information see advisory by Digi International Inc.:\nDigi International Security Notice - TRECK TCP/IP Stack \"RIPPLE20\" VU#257161 ICS-VU-035787 | Digi International ","title":"Summary"},{"category":"description","text":"Pepperl+Fuchs analyzed and identified affected devices.\n\nThe impact on the affected device is that it can\n\n- no longer perform acyclic requests\n- may drop all established cyclic connections may\n- disappear completely from the network","title":"Impact"},{"category":"description","text":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","title":"Mitigation"}],"publisher":{"category":"vendor","contact_details":"cert@pepperl-fuchs.com","name":"Pepperl+Fuchs SE","namespace":"https://www.pepperl-fuchs.com"},"references":[{"category":"external","summary":"Pepperl+Fuchs advisory overview at CERT@VDE","url":"https://certvde.com/de/advisories/vendor/pepperl+fuchs/"},{"category":"self","summary":"VDE-2021-028: Pepperl+Fuchs: Multiple VDM100-Distance Ethernet-IP sensors with multiple vulnerabilities - HTML","url":"https://certvde.com/en/advisories/VDE-2021-028"},{"category":"self","summary":"VDE-2021-028: Pepperl+Fuchs: Multiple VDM100-Distance Ethernet-IP sensors with multiple vulnerabilities - CSAF","url":"https://pepperl-fuchs.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-028.json"}],"title":"Pepperl+Fuchs: Multiple VDM100-Distance Ethernet-IP sensors with multiple vulnerabilities","tracking":{"aliases":["VDE-2021-028"],"current_release_date":"2025-05-14T13:00:14.000Z","generator":{"date":"2025-03-07T11:27:37.765Z","engine":{"name":"Secvisogram","version":"2.5.20"}},"id":"VDE-2021-028","initial_release_date":"2021-08-16T12:01:00.000Z","revision_history":[{"date":"2021-08-16T12:01:00.000Z","number":"1","summary":"Initial revision."},{"date":"2025-05-14T13:00:14.000Z","number":"2","summary":"Fix: added distribution"}],"status":"final","version":"2"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"VDM100-150-EIP/G2","product":{"name":"VDM100-150-EIP/G2","product_id":"CSAFPID-11001","product_identification_helper":{"model_numbers":["243598"]}}},{"category":"product_name","name":"VDM100-300-EIP/G2","product":{"name":"VDM100-300-EIP/G2","product_id":"CSAFPID-11002","product_identification_helper":{"model_numbers":["256831"]}}},{"category":"product_name","name":"VDM100-50-EIP/G2","product":{"name":"VDM100-50-EIP/G2","product_id":"CSAFPID-11003","product_identification_helper":{"model_numbers":["256830"]}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<=2.00","product":{"name":"Firmware <=2.00","product_id":"CSAFPID-21001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Pepperl+Fuchs"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"],"summary":"Affected Products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <=2.00 installed on VDM100-150-EIP/G2","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware <=2.00 installed on VDM100-300-EIP/G2","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware <=2.00 installed on VDM100-50-EIP/G2","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11003"}]},"vulnerabilities":[{"cve":"CVE-2020-11896","cwe":{"id":"CWE-20","name":"Improper Input Validation"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":10,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","temporalScore":10,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11896"},{"cve":"CVE-2020-11897","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":10,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","temporalScore":10,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11897"},{"cve":"CVE-2020-11898","cwe":{"id":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.1,"environmentalSeverity":"CRITICAL","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.1,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11898"},{"cve":"CVE-2020-11901","cwe":{"id":"CWE-20","name":"Improper Input Validation"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.1,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","temporalScore":9,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11901"},{"cve":"CVE-2020-11900","cwe":{"id":"CWE-415","name":"Double Free"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"NONE","environmentalScore":8.2,"environmentalSeverity":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":8.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11900"},{"cve":"CVE-2020-11902","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","environmentalScore":7.3,"environmentalSeverity":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":7.3,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11902"},{"cve":"CVE-2020-11904","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","environmentalScore":7.3,"environmentalSeverity":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":7.3,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11904"},{"cve":"CVE-2020-11905","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","environmentalScore":6.5,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":6.5,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11905"},{"cve":"CVE-2020-11903","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","environmentalScore":6.5,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":6.5,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11903"},{"cve":"CVE-2020-11906","cwe":{"id":"CWE-191","name":"Integer Underflow (Wrap or Wraparound)"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":6.3,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":6.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11906"},{"cve":"CVE-2020-11907","notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":6.3,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":6.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11907"},{"cve":"CVE-2020-11899","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":5.4,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.4,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11899"},{"cve":"CVE-2020-11910","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11910"},{"cve":"CVE-2020-11909","cwe":{"id":"CWE-191","name":"Integer Underflow (Wrap or Wraparound)"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11909"},{"cve":"CVE-2020-11912","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11912"},{"cve":"CVE-2020-11913","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11913"},{"cve":"CVE-2020-11911","cwe":{"id":"CWE-862","name":"Missing Authorization"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11911"},{"cve":"CVE-2020-11908","notes":[{"category":"description","text":"The Treck TCP/IP stack before 4.7.1.27 mishandles '\\0' termination in DHCP.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":4.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":4.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11908"},{"cve":"CVE-2020-11914","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]},"remediations":[{"category":"mitigation","details":"An external protective measure is required.\n\n- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.\n- Isolate affected products from the corporate network.\n- If remote access is required, use secure methods such as virtual private networks (VPNs).","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":4.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":4.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003"]}],"title":"CVE-2020-11914"}]}