Impact
An unbounded parsing routine for PPP IPCP options in NetX Duo allows an attacker to send a crafted packet that triggers an out‑of‑bounds read and stalls a worker thread. The read could expose internal memory contents, while the stall can exhaust system resources and cause service interruption. The vulnerability has a CVSS score of 6, indicating moderate severity.
Affected Systems
Eclipse Foundation: NetX Duo. No specific affected versions are listed in the advisory, so all releases that include the unbounded parsing code are potentially impacted until an explicit fix is applied.
Risk and Exploitability
The CVSS score of 6 signals a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network‑based attacker that injects malformed PPP IPCP options into the device. The exploit requires only network access to the PPP link; no local privileges are needed. If successful, the attacker can either cause a denial of service by flooding the worker thread or read confidential memory, depending on how the out‑of‑bounds read is leveraged.
OpenCVE Enrichment