Description
NULL Pointer Dereference When Evicting the Sole MSRP Attribute
Published: 2026-09-29
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A null pointer dereference occurs when NetX Duo attempts to evict the sole MSRP attribute. This flaw can cause an unexpected crash of the running application or service. The impact is limited to service disruption rather than direct data compromise, but repeated exploitation could lead to denial of service in embedded or real‑time systems.

Affected Systems

The affected product is Eclipse Foundation – NetX Duo. No specific version information is listed, so any installation of NetX Duo that may perform MSRP attribute eviction is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to manipulate MSRP attribute eviction, which typically requires privileged or local access to the device. While the flaw does not directly allow code execution, repeated exploitation could be used for availability attacks.

Generated by OpenCVE AI on September 29, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for NetX Duo as soon as it is released
  • If a patch is not yet available, restrict or disable any functionality that triggers MSRP attribute eviction, limiting exposure to privileged processes
  • Configure monitoring to detect unexpected crashes or service restarts associated with MSRP operations

Generated by OpenCVE AI on September 29, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference During MSRP Attribute Eviction in NetX Duo

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description NULL Pointer Dereference When Evicting the Sole MSRP Attribute
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:33:12.949Z

Reserved: 2026-09-29T16:15:19.231Z

Link: CVE-2026-102724

cve-icon Vulnrichment

Updated: 2026-09-29T18:33:06.654Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:11.960

Modified: 2026-09-29T19:17:22.823

Link: CVE-2026-102724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:00:08Z

Weaknesses