First published: Thu Dec 06 2018(Updated: )
Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGD_SecureConnect_Connect in AWS TLS connectivity modules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Amazon Web Services Freertos | <=1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-16528 is high with a CVSS score of 8.1.
Amazon Web Services (AWS) FreeRTOS up to and including version 1.3.1 is affected by CVE-2018-16528.
Remote attackers can exploit CVE-2018-16528 to execute arbitrary code by corrupting mbedTLS context objects in AWS TLS connectivity modules.
Yes, updates to the Amazon FreeRTOS library are available to address the vulnerability. AWS recommends updating to the latest version (1.3.2) or applying the necessary patches.
More information about CVE-2018-16528 can be found in the following references: [link1], [link2], [link3].