PT-2019-13136 · Amazon · Amazon Freertos

Published

2019-10-07

·

Updated

2022-11-02

·

CVE-2019-13120

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Amazon FreeRTOS versions up to and including 1.4.8
Description The issue is related to a lack of length checking in the prvProcessReceivedPublish function, which can lead to the untargetable leakage of arbitrary memory contents on a device to an attacker. This can occur if an attacker sends a malformed MQTT publish packet to an Amazon IoT Thing that interacts with a vulnerable MQTT message in the application, under specific circumstances.
Recommendations For Amazon FreeRTOS versions up to and including 1.4.8, consider restricting access to the prvProcessReceivedPublish function until a patch is available. As a temporary workaround, avoid using the vulnerable function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2019-13120

Affected Products

Amazon Freertos