CVE-2019-13120 – Amazon FreeRTOS up to and including v1.4.8 for AWS lacks length checking in prvProcessRece …

Vuln ID: CVE-2019-13120

Published:  2019-10-07  22:15:10Z

Description: Amazon FreeRTOS up to and including v1.4.8 for AWS lacks length checking in prvProcessReceivedPublish, resulting in leakage of arbitrary memory contents on a device to an attacker. An attacker sends a malformed MQTT publish packet, and waits for an MQTTACK packet containing the leaked data.

Source: NVD.NIST.GOV

 

Tags