Eclipse Foundation NetX Duo
cpe:2.3:a:eclipse:threadx_netx_duo:*:*:*:*:*:*:*
- <= 6.4.3
A moderate off-by-one out-of-bounds read vulnerability has been identified in Eclipse NetX Duo versions through 6.4.3. The issue arises in the function '_nx_secure_tls_proc_clienthello_supported_versions_extension()', which improperly validates the length of version extensions in TLS packets. This flaw can potentially be exploited to read memory out of bounds, leading to undefined behavior.
Exploitation of this vulnerability causes an off-by-one out-of-bounds read, which can lead to memory corruption or information disclosure.
Users can upgrade to NetX Duo version 6.4.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.