Flaw in FreeRTOS and WITTENSTEIN WHIS Connect TCP/IP Component
CVE-2018-16598
5.9MEDIUM
What is CVE-2018-16598?
A vulnerability exists in Amazon Web Services FreeRTOS and WITTENSTEIN WHIS Connect middleware that allows the acceptance of any received DNS response without verifying if it matches the originally sent DNS request. This flaw could enable attackers to exploit the system through improper handling of DNS packets, potentially leading to unauthorized access or malicious data interception.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved