Impact
The vulnerability causes an out-of-bounds write during the TLS 1.3 handshake when a client processes a message larger than the cache buffer in the NetX Duo TLS stack. The write corrupts the session control block, which holds internal pointers, potentially allowing a malicious server to overwrite memory prior to certificate verification. This can result in application crash, denial of service, or, under certain conditions, arbitrary code execution. The CVSS score of 9.3 reflects the severity of this issue.
Affected Systems
The affected product is Eclipse ThreadX NetX Duo 6.5.1.202602, released by the Eclipse Foundation. No other versions or products are listed as affected in the available data.
Risk and Exploitability
The risk is high because the flaw is exploitable over a TLS connection that does not require a trusted server certificate. The EPSS score is not provided, and the vulnerability is not yet listed in CISA KEV, but the CVSS score indicates a significant likelihood of exploitation if a malicious server can initiate a handshake. The attack vector is remote; any TLS 1.3 client that accepts handshake messages from a remote server can trigger the out-of-bounds write. The impact includes potential code execution and data corruption, posing a serious threat to affected systems.
OpenCVE Enrichment