Out of Bound Read Vulnerability in NetX Duo by Eclipse Foundation
CVE-2025-55082
6.9MEDIUM
What is CVE-2025-55082?
In versions of NetX Duo prior to 6.4.4, a potential out of bounds read exposure exists within the Eclipse Foundation's ThreadX component. This vulnerability arises due to insufficient validation of the Pre-Shared Key (PSK) length in the user-provided message during the execution of the _nx_secure_tls_process_clienthello() function. Consequently, this could lead to unintended access to memory beyond the allocated bounds, potentially compromising system integrity and security.
Affected Version(s)
NetX Duo 0 < 6.4.4
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Justin Stauffer
Ilya van Sprundel
