CVE-2018-16600: Infoleak
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of ARP packets in eARPProcessPacket can be used for information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16600?
CVE-2018-16600 is a vulnerability in Amazon Web Services (AWS) FreeRTOS and WITTENSTEIN WHIS Connect middleware TCP/IP component that allows out of bounds memory access during parsing of ARP packets, leading to information disclosure.
What software is affected by CVE-2018-16600?
CVE-2018-16600 affects Amazon Web Services (AWS) FreeRTOS versions up to 1.3.1 and FreeRTOS versions up to V10.0.1 (with FreeRTOS+TCP).
What is the severity of CVE-2018-16600?
CVE-2018-16600 has a severity level of medium, with a CVSSv3 score of 5.9.
How can CVE-2018-16600 be exploited?
CVE-2018-16600 can be exploited by sending specially crafted ARP packets to the vulnerable system, allowing an attacker to access out of bounds memory and potentially disclose sensitive information.
How can I fix CVE-2018-16600?
To fix CVE-2018-16600, users should update to the latest version of Amazon Web Services (AWS) FreeRTOS and FreeRTOS, which have patched the vulnerability.