« Volver al listado

Eclipse

Eclipse Threadx: vulnerabilidades y CVE

Eclipse Threadx tiene 9 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses7
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-102714Alta (7.1)0.15%—29 sept 2026
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail…
CVE-2026-102711Media (5.7)0.07%—29 sept 2026
Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base…
CVE-2026-102710Crítica (9.3)0.10%—29 sept 2026
Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can…
CVE-2026-0648Media (6.3)0.12%—27 ene 2026
The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the return value of osek_get_counter().…
CVE-2025-55080Alta (7.2)0.14%—15 oct 2025
In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.
CVE-2025-55079Media (5.7)0.17%—15 oct 2025
In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a result, to obtain a thread with higher…
CVE-2025-55078Media (5.7)0.17%—14 oct 2025
In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check…
CVE-2024-2214Alta (7.8)0.34%—26 mar 2024
In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected file was ports/xtensa/xcc/src/tx_clib_lock.c
CVE-2024-2212Alta (7.8)0.54%—26 mar 2024
In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System2
  2. T1068 Exploitation for Privilege Escalation2
  3. T1203 Exploitation for Client Execution1
  4. T1210 Exploitation of Remote Services1
  5. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Eclipse