CVE-2024-40493
22.10.2024, 22:15
Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a specially crafted CoAP packet that causes `coap_msg_get_payload(resp)` to return a null pointer, which is then dereferenced in a call to `memcpy`.Enginsight
Vendor | Product | Version |
---|---|---|
keith-cullen | freecoap | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration