Hcc Embedded maintains a focused portfolio of embedded networking and TCP/IP stack products, including NicheStack and InNiche variants, that serve niche deployment contexts where customized protocol implementations are required. The vendor's vulnerability surface reflects the complexity of network protocol handling in resource-constrained and legacy embedded environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hcc Embedded over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25928CRITICAL The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing fun | Aug 18, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-31226CRITICAL An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to lack of size validation. Thi | Aug 19, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-35685CRITICAL An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As | Aug 19, 2021 | 9.1 | 27 | NO | NO |
CVE-2020-25927HIGH The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of service (remote). The component is: DNS response processing in | Aug 18, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-25767HIGH An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does not check whether a domain name compression pointer is pointi | Aug 18, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-25926HIGH The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: | Aug 18, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-36762HIGH An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' | Aug 19, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-31401HIGH An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't sanitize the value of the IP total length field (header len | Aug 19, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-27565HIGH The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP reques | Aug 19, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-35684HIGH An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the le | Aug 19, 2021 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hcc Embedded.
Media articles that mention a CVE ID that affects a product developed by Hcc Embedded — matched by CVE ID, not by vendor name.