PT-2020-11896 · Zephyr · Zephyr

Published

2020-06-05

·

Updated

2020-06-12

·

CVE-2020-10070

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zephyr version 2.2.0 and later versions
Description The issue is related to improper bounds checking in the Zephyr Project MQTT code, which can lead to memory corruption and possibly remote code execution.
Recommendations For zephyr version 2.2.0 and later versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10070

Affected Products

Zephyr