An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds access to TCP source and destination port fields in xProcessReceivedTCPPacket can leak data back to an attacker.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"extracted_events": [
{
"last_affected": "10.0.1"
}
],
"cpes": [
"cpe:2.3:a:amazon:freertos:*:*:*:*:*:*:*:*"
],
"vendor_product": "amazon:freertos"
}
]
}{
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.3.1"
}
],
"cpe": "cpe:2.3:a:amazon:amazon_web_services_freertos:*:*:*:*:*:*:*:*"
}