Out-of-Bounds Write Vulnerability in NXP MQX Classic Software
CVE-2017-20283

6.5MEDIUM

Key Information:

Vendor

Nxp

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2017-20283?

NXP MQX Classic prior to version 5.0 is affected by an out-of-bounds write vulnerability in the RTCS UDP recvfrom() function, which allows for improper handling of the user-defined receive buffer length. An attacker can exploit this flaw by sending specially crafted UDP packets that overflow the allocated memory buffer. This can lead to memory corruption, potentially allowing for abnormal application behavior or service disruptions.

Affected Version(s)

MQX 0 < 5.0 Classic

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.