Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Keith-cullen
Keith-cullen freecoap |
|
| CPEs | cpe:2.3:a:keith-cullen:freecoap:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Keith-cullen
Keith-cullen freecoap |
Wed, 23 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Keithcullen
Keithcullen freecoap |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:keithcullen:freecoap:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Keithcullen
Keithcullen freecoap |
|
| Metrics |
cvssV3_1
|
Tue, 22 Oct 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a specially crafted CoAP packet that causes `coap_msg_get_payload(resp)` to return a null pointer, which is then dereferenced in a call to `memcpy`. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-23T15:50:04.486Z
Reserved: 2024-07-05T00:00:00.000Z
Link: CVE-2024-40493
Updated: 2024-10-23T15:49:57.551Z
Status : Analyzed
Published: 2024-10-22T22:15:04.407
Modified: 2024-10-25T17:01:22.433
Link: CVE-2024-40493
No data.
OpenCVE Enrichment
No data.