PT-2020-11871 · Zephyr · Zephyr

Andrew Boie

+1

·

Published

2020-05-11

·

Updated

2020-06-05

·

CVE-2020-10028

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zephyr versions 1.14.0 and later zephyr versions 2.1.0 and later
Description The issue is related to multiple syscalls with insufficient argument validation. This problem affects the zephyrproject-rtos.
Recommendations For zephyr version 1.14.0 and later, update to a version that includes the fix for this issue. For zephyr version 2.1.0 and later, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10028

Affected Products

Zephyr