A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25066
Reference (s):
- https://security.netapp.com/advisory/ntap-20210201-0003/
- https://treck.com/vulnerability-response-information/

