CVE-2020-13602: Remote Denial of Service in LwM2M do_write_op_tlv
Published May 24, 2021
·Updated
Remote Denial of Service in LwM2M dowriteoptlv. Zephyr versions >= 1.14.2, >= 2.2.0 contain Improper Input Validation (CWE-20), Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-g9mg-fj58-6fqh
Affected Software
2 affected components
zephyrproject zephyr<=1.14.2
zephyrproject zephyr>=2.0.0<=2.2.0
Event History
May 24, 2021
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-13602.
2
What is the severity level of CVE-2020-13602?
The severity level of CVE-2020-13602 is medium (5.5).
3
What is the affected software for CVE-2020-13602?
The affected software for CVE-2020-13602 are Zephyr versions >= 1.14.2 and >= 2.2.0.
4
What is the CWE ID associated with CVE-2020-13602?
The CWE IDs associated with CVE-2020-13602 are CWE-20 and CWE-835.
5
How can I fix the vulnerability CVE-2020-13602?
To fix the vulnerability CVE-2020-13602, it is recommended to upgrade to a version of Zephyr that is not affected by this issue.