NULL Pointer Dereference in Apache NuttX ftpd Component
CVE-2020-1939

9.8CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
12 May 2020

Summary

A NULL pointer dereference vulnerability found in the ftpd component of the Apache NuttX project affects users utilizing the optional apps repository. This flaw occurs when ftpd is enabled, leading to potential disruptions in the service. The affected versions range from 6.15 to 8.2. Despite its impact, the core NuttX RTOS remains unaffected, as the vulnerability is isolated to the optional ftpd application.

Affected Version(s)

Apache NuttX (incubating) Apache NuttX (incubating) 6.15 to 8.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.