Amazon Web Services (AWS) FreeRTOS attraverso 1.3.1, FreeRTOS fino a V10.0.1 (con FreeRTOS + TCP), e componente WITTENSTEIN WHIS Connect middleware TCP / IP consentono la divulgazione di informazioni durante l’analisi dei pacchetti ICMP nel prvProcessICMPPacket. |
https://github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.md https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-details/ https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16527 |
Vulnerabilità: CVE-2018-16527
