Out of Bounds Access Vulnerability in AWS FreeRTOS and WITTENSTEIN WHIS Connect
CVE-2018-16603
5.9MEDIUM
What is CVE-2018-16603?
An out of bounds access vulnerability has been identified in AWS FreeRTOS versions through 1.3.1, as well as in versions of FreeRTOS up to V10.0.1 that utilize the FreeRTOS+TCP component, along with the WITTENSTEIN WHIS Connect middleware's TCP/IP functionality. This issue occurs in the xProcessReceivedTCPPacket function where attackers can exploit the improper handling of TCP source and destination port fields, potentially leading to the leakage of sensitive data. The vulnerability poses risks to a wide range of devices, highlighting security concerns in both smart home and critical infrastructure environments.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved