CVE-2024-2452

HIGH

Eclipse ThreadX NetX Duo <6.4.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.

Scores

CVSS v3 7.0
EPSS 0.0014
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190 CWE-120
Status published
Products (1)
eclipse/threadx_netx_duo < 6.4.0
Published Mar 26, 2024
Tracked Since Feb 18, 2026