Eclipse Foundation NetX Duo
cpe:2.3:a:eclipse:threadx_netx_duo:*:*:*:*:*:*:*
- <= 6.4.3
A high-severity out-of-bounds read vulnerability has been identified in the HTTP client module of NetX Duo, prior to version 6.4.4. The issue arises from the lack of bounds checking when parsing HTTP header fields, allowing a crafted server response to manipulate pointer values and potentially lead to undefined behavior, such as memory corruption or system crashes.
Exploitation of this vulnerability could cause system crashes or memory corruption, leading to undefined behavior.
Users can upgrade to NetX Duo version 6.4.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.