Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.18% | — | Amazon Freertos | 21/8/2026 | 25/8/2026 | Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Alta (8.3) | 0.16% | — | Amazon Freertos | 21/8/2026 | 25/8/2026 | Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Alta (8.3) | 0.16% | — | Amazon Freertos | 21/8/2026 | 27/8/2026 | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Crítica (9.3) | 0.17% | — | Amazon Freertos | 21/8/2026 | 27/8/2026 | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Alta (8.7) | 0.68% | — | Freertos Coremqtt | 15/5/2026 | 17/6/2026 | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1. | |
| Analizada | Media (6.1) | 0.40% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length, resulting in a… | |
| Analizada | Media (6) | 0.38% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smaller than the expected… | |
| Analizada | Alta (7.2) | 0.37% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) by sending a single… | |
| Analizada | Media (6) | 0.36% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the field is… | |
| Analizada | Alta (7.1) | 0.29% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mechanism skips all input… | |
| Analizada | Media (5.3) | 0.34% | — | Amazon Freertos-plus-tcp | 10/10/2025 | 17/6/2026 | A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. This issue only affects applications using IPv6. We recommend upgrading to the latest version and ensure… | |
| Analizada | Media (5.3) | 0.31% | — | Amazon Freertos-plus-tcp | 10/10/2025 | 17/6/2026 | A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We recommend users upgrade to the latest version and ensure any forked or… | |
| Analizada | Media (5.3) | 0.31% | — | Amazon Freertos-plus-tcp | 10/10/2025 | 17/6/2026 | A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using IPv6. Users should upgrade to the latest version and ensure any… | |
| Modificada | Alta (8.1) | 0.61% | — | Amazon Freertos-plus-tcp | 24/6/2024 | 17/6/2026 | FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with domain name length value greater than the actual domain name… | |
| Modificada | Alta (7.8) | 0.24% | — | Amazon Freertos | 7/3/2024 | 17/6/2026 | FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows code injection and execution. These issues affect ARMv7-M MPU ports,… | |
| Modificada | Alta (7.8) | 0.28% | — | Amazon FreertosTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 21/11/2023 | 17/6/2026 | Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution. | |
| Modificada | Alta (7.8) | 0.34% | — | Amazon Freertos | 17/11/2021 | 17/6/2026 | FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected code to achieve further privilege… | |
| Modificada | Crítica (9.8) | 1.3% | — | Amazon Freertos | 3/5/2021 | 17/6/2026 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory. | |
| Modificada | Crítica (9.8) | 1.4% | — | Amazon Freertos | 22/4/2021 | 17/6/2026 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer. | |
| Modificada | Crítica (9.8) | 1.4% | — | Amazon Freertos | 22/4/2021 | 17/6/2026 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation. | |
| Modificada | Alta (7.5) | 0.92% | — | Amazon Freertos+fat | 4/11/2019 | 17/6/2026 | Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definition of vPortFree(), but it is reused to flush modified file content from the cache to disk by the function… | |
| Modificada | Alta (7.5) | 1.2% | — | Amazon WEB Services Freertos | 7/10/2019 | 17/6/2026 | Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an… | |
| Modificada | Media (5.9) | 1.8% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds access to TCP source and destination port fields in xProcessReceivedTCPPacket can leak data back to an attacker. | |
| Modificada | Media (5.9) | 1.8% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of DHCP responses in prvProcessDHCPReplies can be used for information disclosure. | |
| Modificada | Alta (8.1) | 4.2% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memory space copy in prvProcessIPPacket, leading to denial of service and possibly remote code execution. |