CVE-2018-16528: Input Validation
Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGDSecureConnectConnect in AWS TLS connectivity modules.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16528?
The severity of CVE-2018-16528 is high with a CVSS score of 8.1.
What software is affected by CVE-2018-16528?
Amazon Web Services (AWS) FreeRTOS up to and including version 1.3.1 is affected by CVE-2018-16528.
How can remote attackers exploit CVE-2018-16528?
Remote attackers can exploit CVE-2018-16528 to execute arbitrary code by corrupting mbedTLS context objects in AWS TLS connectivity modules.
Are there any known fixes or patches for CVE-2018-16528?
Yes, updates to the Amazon FreeRTOS library are available to address the vulnerability. AWS recommends updating to the latest version (1.3.2) or applying the necessary patches.
Where can I find more information about CVE-2018-16528?
More information about CVE-2018-16528 can be found in the following references: [link1], [link2], [link3].