PT-2018-13616 · Amazon Web Services+1 · Freertos+1

Ori Karliner

+1

·

Publicado

2018-12-06

·

Atualizado

2019-02-01

·

CVE-2018-16528

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amazon Web Services (AWS) FreeRTOS versions prior to 1.3.2
Description The issue allows remote attackers to execute arbitrary code due to mbedTLS context object corruption in the prvSetupConnection and GGD SecureConnect Connect functions within AWS TLS connectivity modules.
Recommendations For versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the AWS TLS connectivity modules until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16528

Produtos afetados

Freertos
Mbed Tls