CVE-2021-27504

EUVD-2021-14258
Texas Instruments devices running FREERTOS, malloc returns a valid 
pointer to a small buffer on extremely large values, which can trigger 
an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in
 code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
7.4 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
Affected Products (NVD)
VendorProductVersion
amazonfreertos
10.4.1
tisimplelink_cc13xx_software_development_kit
𝑥
< 4.40.00
tisimplelink_cc26xx_software_development_kit
𝑥
< 4.40.00
tisimplelink_cc32xx_software_development_kit
𝑥
< 4.10.03
tisimplelink_msp432e401y
-
tisimplelink_msp432e411y
-
𝑥
= Vulnerable software versions