← Back to CVE List

CVE-2019-13120

Published: 2019-10-07T22:15Z
Last Modified: 2024-11-21T04:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt