PT-2020-11892 · Zephyr · Zephyr

Published

2020-06-05

·

Updated

2020-06-12

·

CVE-2020-10062

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zephyr version 2.2.0 and later versions
Description An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution.
Recommendations For zephyr version 2.2.0 and later versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10062

Affected Products

Zephyr