Impact
The vulnerability is a null pointer dereference triggered when the MSRP attribute table is exhausted, leading to a crash of the NetX Duo networking stack. The resulting instability manifests as a denial of service, disabling functionality that relies on the affected component. This flaw is categorized as CWE‑476.
Affected Systems
Eclipse Foundation’s NetX Duo embedded networking stack is affected. The advisory does not list specific version numbers, but any deployment that includes the MSRP attribute handling code remains vulnerable unless a patch or update is applied.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity. Because the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, widespread exploitation is not known. The attack vector is likely to involve an attacker sending a sequence of MSRP packets designed to exhaust the table, which is inferred from the description of table exhaustion. If successful, the attacker can cause the component to crash, resulting in a denial‑of‑service condition. No evidence of active exploitation exists at this time.
OpenCVE Enrichment