peter bassill · operator
$ cve CVE-2020-17528 JSON

CVE-2020-17528

9.1
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS3.17% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2020-12-09
Last modified2026-06-17

Affected (1)

VendorProduct
apachenuttx

References

→ the Explorer  ·  watch your stack  ·  NVD