Buffer Overflow Vulnerability in Amazon Web Services FreeRTOS and WITTENSTEIN WHIS Connect
CVE-2018-16525

8.1HIGH

Key Information:

Vendor

Amazon

Vendor
CVE Published:
6 December 2018

What is CVE-2018-16525?

A vulnerability exists in Amazon Web Services FreeRTOS versions up to 1.3.1, FreeRTOS up to V10.0.1 with FreeRTOS+TCP, and the WITTENSTEIN WHIS Connect middleware. This issue allows remote attackers to execute arbitrary code or leak sensitive information. The vulnerability arises during the parsing of DNS and LLMNR packets, specifically within the function 'prvParseDNSReply', leading to potential compromise of devices utilizing these systems.

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.