CVE-2018-16601
A crafted IP header triggers a full memory space copy in prvProcessIPPacket, leading to denial of service and possibly remote code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memory space copy in prvProcessIPPacket, leading to denial of service and possibly remote code execution.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.16% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-191
- Affected
- amazon/amazon web services freertos · amazon/freertos
- Source
- cve@mitre.org
References
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-details/Exploit, Third Party Advisory
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/Third Party Advisory
- https://github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.mdRelease Notes, Third Party Advisory
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-details/Exploit, Third Party Advisory
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/Third Party Advisory
- https://github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.mdRelease Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.