Azure RTOS USBX Remote Code Execution Vulnerability
CVE-2023-48696
9.8CRITICAL
What is CVE-2023-48696?
The Azure RTOS USBX stack contains a vulnerability that allows remote code execution due to expired pointer dereference issues. This affects components in the host class, specifically related to CDC ACM in versions v6.2.1 and earlier. Users must upgrade to USBX release 6.3.0 to mitigate this risk, as no workarounds are available.
Affected Version(s)
usbx < 6.3.0