Lucene search

K
cvelistMitreCVELIST:CVE-2019-13120
HistoryOct 07, 2019 - 9:57 p.m.

CVE-2019-13120

2019-10-0721:57:48
mitre
www.cve.org
4

EPSS

0.002

Percentile

53.8%

Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability.

EPSS

0.002

Percentile

53.8%

Related for CVELIST:CVE-2019-13120