First published: Mon Oct 07 2019(Updated: )
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Amazon Web Services Freertos | <=1.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13120 is a vulnerability in Amazon FreeRTOS up to and including v1.4.8 that lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents to an attacker.
CVE-2019-13120 has a severity score of 7.5, which is considered high.
Versions up to and including v1.4.8 of Amazon FreeRTOS are affected by CVE-2019-13120.
The Common Weakness Enumeration (CWE) for CVE-2019-13120 is CWE-125.
To mitigate CVE-2019-13120, it is recommended to update Amazon FreeRTOS to a version that includes the fix.