CVE-2019-13120
07.10.2019, 22:15
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
amazon | amazon_web_services_freertos | 𝑥 ≤ 1.4.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration