CVE-2020-10062: Packet length decoding error in MQTT
An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10062?
CVE-2020-10062 has a high severity level due to its potential to cause memory corruption and allow remote code execution.
How do I fix CVE-2020-10062?
To fix CVE-2020-10062, upgrade the Zephyr version to 2.2.1 or later, which addresses the vulnerability.
What systems are affected by CVE-2020-10062?
CVE-2020-10062 affects the Zephyr project MQTT packet length decoder in Zephyr versions 2.2.0 and earlier.
What is the nature of the vulnerability in CVE-2020-10062?
The vulnerability in CVE-2020-10062 is an off-by-one error that can lead to memory corruption.
Can CVE-2020-10062 lead to remote code execution?
Yes, CVE-2020-10062 can potentially allow remote code execution due to its memory corruption impact.