QID 11646
Date Published: 2021-11-17
QID 11646: Amazon Web Services (AWS) FreeRTOS Buffer Overflow Vulnerability
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to execute arbitrary code or leak information because of a Buffer Overflow during parsing of DNS\LLMNR packets in prvParseDNSReply.
Affected Versions:
Amazon Web Services (AWS) FreeRTOS upto 1.3.1
QID detection logic:
Qid checks for the vulnerable banner of FreeRTOS on HTTP service.
Allows remote attackers to execute arbitrary code or leak information because of a Buffer Overflow.
Solution
Customers are advised to upgrade to AWS FreeRTOS or later versions to remediate these vulnerabilities.
Vendor References
- AWS FreeRTOS -
github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.md
CVEs related to QID 11646
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AWS FreeRTOS |
|