FreeRTOS TCP/IP Stack Vulnerabilities
ID: 2b43fa89-fd94-5b74-a5bd-ee14c8bf7a47
STIX ID: report--2b43fa89-fd94-5b74-a5bd-ee14c8bf7a47
Feed Name: Zimperium Blog
This Zimperium disclosure (researcher Ori Karliner) documents multiple vulnerabilities in FreeRTOS+TCP and AWS secure sockets (numerous CVEs) that enable information leakage, denial-of-service, memory corruption and remote code execution depending on configuration and allocation scheme; affected flows include TLS/mbedTLS misuse, UDP/DNS/LLMNR/NBNS parsing, IP/TCP/ARP/ICMP/DHCP handling and TCP options parsing. The report gives technical analysis of vulnerable functions and exploitation primitives, notes the impact varies by buffer allocation scheme, and advises reviewing source code and contacting [email protected] for assessments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
