Impact
A null pointer dereference occurs when NetX Duo attempts to evict the sole MSRP attribute. This flaw can cause an unexpected crash of the running application or service. The impact is limited to service disruption rather than direct data compromise, but repeated exploitation could lead to denial of service in embedded or real‑time systems.
Affected Systems
The affected product is Eclipse Foundation – NetX Duo. No specific version information is listed, so any installation of NetX Duo that may perform MSRP attribute eviction is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to manipulate MSRP attribute eviction, which typically requires privileged or local access to the device. While the flaw does not directly allow code execution, repeated exploitation could be used for availability attacks.
OpenCVE Enrichment