CVE-2023-48315

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 5, 2023
Updated: Dec 8, 2023
CWE ID 787
CWE ID 825

Summary

CVE-2023-48315 is a critical vulnerability affecting Azure RTOS NetX Duo, a TCP/IP network stack commonly used in deeply embedded real-time and IoT applications. This issue allows remote code execution due to memory overflow vulnerabilities, specifically in the FTP and SNTP components of RTOS v6.2.1 and below. Attackers can exploit this flaw to execute malicious code on the targeted devices. To mitigate this risk, users are advised to upgrade to the latest release, NetX Duo 6.3.0, as soon as possible. No known workarounds exist for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share