Vulnerabilities > CVE-2018-16601 - Integer Underflow (Wrap or Wraparound) vulnerability in Amazon web Services Freertos and Freertos
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memory space copy in prvProcessIPPacket, leading to denial of service and possibly remote code execution.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-details/
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-details/
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/
- https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/
- https://github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.md
- https://github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.md