VYPR
Unrated severityNVD Advisory· Published Feb 12, 2024· Updated Nov 7, 2024

Azure IoT Platform Device SDK Remote Code Execution Vulnerability

CVE-2024-25110

Description

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit 30865c9c. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.