Improper Handling of Length Parameter Inconsistency in TCP/IP stack - CVE-2020-11898
Published: June 17, 2020 / Updated: June 9, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information or perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of length parameter inconsistency in Pv4/ICMPv4 component. A remote attacker can send a specially crafted packet and trigger out-of-bounds read, leading to information disclosure or denial of service condition.
Affected software
PowerFlex rack
How to mitigate CVE-2020-11898
PowerFlex rack - addressed in versions 3.3.8.2, 3.4.3.2, 3.5.3.2