Impact
The vulnerability lies in NetX Duo’s handling of an MSRP attribute length. The unvalidated length can cause an out-of-bounds read, exposing memory contents to an attacker. This flaw falls under CWE‑125 and can lead to information disclosure.
Affected Systems
Affected products are systems running the Eclipse Foundation NetX Duo real‑time operating system. Version information is not listed in the advisory, so any deployment of NetX Duo is potentially impacted unless later patches are applied.
Risk and Exploitability
The CVSS score of 6.0 marks the flaw as moderate severity. No EPSS data is available, and the vulnerability is not recorded in CISA KEV, indicating there is no public exploitation evidence yet. Nonetheless, an attacker who can supply or influence MSRP attributes—either through a local connection or a network interface—might exploit the out-of-bounds read. The exact attack vector is not detailed in the advisory, but it is likely to require privileged access to send crafted MSRP data.
OpenCVE Enrichment