First published: Fri Jun 05 2020(Updated: )
A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of service. This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | <=2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-10063 is high with a CVSS score of 7.5.
CVE-2020-10063 allows a remote adversary to cause a denial of service by sending arbitrary CoAP packets to be parsed by Zephyr.
Zephyr version 2.2.0 and later versions are affected by CVE-2020-10063.
The fix for CVE-2020-10063 can be found in the Zephyr project's GitHub repository. It is recommended to update to the latest version of Zephyr that includes the fix.
More information about CVE-2020-10063 can be found in the Zephyr project's security vulnerabilities documentation.