Unrated severityOSV Advisory· Published Dec 6, 2018· Updated Aug 5, 2024
CVE-2018-16602
CVE-2018-16602
Description
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of DHCP responses in prvProcessDHCPReplies can be used for information disclosure.
Affected products
1- Range: v1.0.0, v1.1.0, v1.2.0, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-details/mitrex_refsource_MISC
- blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/mitrex_refsource_MISC
- github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.mdmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.