Eclipse Foundation NetX Duo
cpe:2.3:a:eclipse:threadx_netx_duo:*:*:*:*:*:*:*
- <= 6.4.3
A moderate out-of-bounds read vulnerability has been identified in Eclipse Foundation NetX Duo versions prior to 6.4.4. The issue arises in the networking support module for Eclipse Foundation ThreadX, specifically within the '_nx_ipv4_option_process()' function. When processing IPv4 packets with the timestamp option, the function lacks proper bounds checking, allowing it to read three bytes beyond the intended limit. This flaw could potentially be exploited to access out-of-bounds memory.
Exploitation of this vulnerability could lead to unauthorized memory access, potentially allowing for information disclosure or manipulation.
Users can upgrade to Eclipse Foundation NetX Duo version 6.4.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.