FreeRTOS-Plus-TCP
cpe:2.3:a:amazon:freertos-plus-tcp:*:*:*:*:*:*:*
- >= V4.0.0, <= V4.2.5
- >= V4.3.0, <= V4.4.0
A denial-of-service vulnerability has been identified in FreeRTOS-Plus-TCP versions 4.0.0 through 4.2.5 and 4.3.0 through 4.4.0. The issue arises from insufficient validation of option lengths in the IPv6 Router Advertisement parser. This flaw allows an adjacent network actor to send a crafted Router Advertisement with a truncated PREFIX_INFORMATION option, causing a device crash.
Exploitation of this vulnerability leads to a device crash, causing a denial-of-service condition.
Users are advised to upgrade to FreeRTOS-Plus-TCP versions 4.2.6 or 4.4.1. If an immediate upgrade is not possible, consider implementing network-level filtering to block untrusted Router Advertisement packets or deploying devices on isolated network segments where rogue Router Advertisement packets cannot be injected.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.