Heap Buffer Overflow Vulnerability in Eclipse ThreadX NetX Duo Before 6.4.0
CVE-2024-2452
9.8CRITICAL
What is CVE-2024-2452?
A vulnerability exists in Eclipse ThreadX NetX Duo prior to version 6.4.0, where manipulation of parameters in the __portable_aligned_alloc() function can lead to an integer wrap-around. This condition may inadvertently allocate memory smaller than intended, resulting in the potential for heap buffer overflows. Such overflows can allow attackers to execute arbitrary code, potentially compromising the system’s integrity and confidentiality.
Affected Version(s)
ThreadX 0 < 6.4.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Ivaldi
