CVE-2020-10022
UpdateHub Module Copies a Variable-Size Hash String Into a Fixed-Size Array
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of service in the best case, or code execution in the worst case. See NCC-NCC-016 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions. version 2.2.0 and later versions.
Una carga útil JSON malformada que es recibida desde un servidor UpdateHub puede desencadenar una corrupción de la memoria en el Sistema Operativo Zephyr. Esto podría resultar en una denegación de servicio en el mejor de los casos, o una ejecución de código en el peor de los casos. Consulte NCC-NCC-016. Este problema afecta a: zephyrproject-rtos zephyr versión 2.1.0 y versiones posteriores. Versión 2.2.0 y versiones posteriores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-03 CVE Reserved
- 2020-05-11 CVE Published
- 2024-02-19 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://docs.zephyrproject.org/latest/security/vulnerabilities.html#cve-2020-10022 | X_refsource_misc | |
https://zephyrprojectsec.atlassian.net/browse/ZEPSEC-28 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/zephyrproject-rtos/zephyr/pull/24065 | 2020-06-05 | |
https://github.com/zephyrproject-rtos/zephyr/pull/24066 | 2020-06-05 | |
https://github.com/zephyrproject-rtos/zephyr/pull/24154 | 2020-06-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zephyrproject Search vendor "Zephyrproject" | Zephyr Search vendor "Zephyrproject" for product "Zephyr" | 2.1.0 Search vendor "Zephyrproject" for product "Zephyr" and version "2.1.0" | - |
Affected
| ||||||
Zephyrproject Search vendor "Zephyrproject" | Zephyr Search vendor "Zephyrproject" for product "Zephyr" | 2.2.0 Search vendor "Zephyrproject" for product "Zephyr" and version "2.2.0" | - |
Affected
|