CVE-2021-27504

Texas Instruments devices running FREERTOS, malloc returns a valid 
pointer to a small buffer on extremely large values, which can trigger 
an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in
 code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
7.4 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
VendorProductVersion
amazonfreertos
10.4.1
tisimplelink_cc13xx_software_development_kit
𝑥
< 4.40.00
tisimplelink_cc26xx_software_development_kit
𝑥
< 4.40.00
tisimplelink_cc32xx_software_development_kit
𝑥
< 4.10.03
tisimplelink_msp432e401y
-
tisimplelink_msp432e411y
-
𝑥
= Vulnerable software versions