SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1939

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs.

CRITICAL 9.8EPSS 2.50%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the optional apps repository are affected only if they have enabled ftpd. Versions 6.15 to 8.2 are affected.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.50% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
apache/nuttx
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.