ExtraHop named a Leader in the 2025 Forrester Wave™: Network Analysis And Visibility Solutions

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

FreeBSD Exploit Attempt - CVE-2020-25577

Risk Factors

An attacker must have local network access to a vulnerable device. An attacker can employ publicly available exploit code to launch an attack. A successful exploit can lead to a denial of service (DoS) scenario or enable an attacker to gain control of a device.

Category

Exploitation
Detection diagram
Next in Exploitation: FreeBSD Exploit Attempt - CVE-2020-25583

Attack Background

The Neighbor Discovery Protocol (NDP) facilitates host-router discovery and DNS configuration for IPv6 addresses. ICMPv6 message types defined by NDP help to identify relationships between devices in an IPv6 network. One of these message types is a Router Advertisement (message type 134), which includes a Recursive DNS Server (RDNSS) option for including DNS server information. The router solicitation daemon (rtsold) in FreeBSD has a vulnerability in how it processes incoming ICMPv6 Router Advertisement messages. An attacker creates a malicious message with a manipulated RDNSS option field. If the RDNSS option is zero, rtsold continues to process the message in an infinite loop, causing a denial of service (DoS). If the RDNSS option length is too large, rtsold performs an out-of-bounds read, which could lead to remote command execution (RCE).

Mitigation Options

Install relevant patches for affected devices

MITRE ATT&CK ID

Associated content

Announcing The Forrester Wave™: Network Analysis And Visibility Solutions, Q4 2025

Network analysis and visibility solutions remain underrepresented in enterprises. Find out why in this preview of a new Wave report.

Report

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response — ExtraHop

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response

News

Detections

Visit this resource for more information.

Docs

The 2025 ExtraHop Global Threat Landscape Report: The Alarming Reality of Threat Actor Dwell Time and Deeper Network Access — ExtraHop

This analysis exposes the critical link between an organization's lack of internal visibility and the escalating cost of compromise, demanding an urgent re-evaluation of how core business assets are protected.

Blog

ExtraHop RevealX MITRE ATT&CK Coverage 2024 — ExtraHop

Learn why you need to be wary of the claims certain network detection and response providers make about their coverage against the MITRE ATT&CK framework.

Blog

MITRE ATT&CK - Network Detection & Response with RevealX — ExtraHop

Learn how NDR from RevealX helps security teams detect and investigate more adversary TTPs in the MITRE ATT&CK framework than rule-based tools.

External
Periodic Table of Use Cases

What else can RevealX do for you?