CVE-2020-22283 is a buffer overflow vulnerability in the lwIP TCP/IP stack, specifically within the icmp6_send_response_with_addrs_and_netif() function, affecting lwIP version git head. This flaw allows an unauthenticated attacker to access sensitive information by sending a specially crafted ICMPv6 packet. Rated 7.5 HIGH, it has a low attack complexity and high confidentiality impact, but no integrity or availability impact. There is currently no public exploit code, evidence of active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:lwip_project:lwip:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.