

Amazon FreeRTOS up to and including v1.4.8 for AWS lacks length checking in prvProcessReceivedPublish, resulting in leakage of arbitrary memory contents on a device to an attacker. An attacker sends a malformed MQTT publish packet, and waits for an MQTTACK packet containing the leaked data.

Source: CVE-2019-13120

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다