Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38562


A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.


Published

2024-02-20T15:15:08.020

Last Modified

2025-02-12T18:51:08.283

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.7 (HIGH)

Weaknesses
  • Type: Primary
    CWE-415

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application weston-embedded uc-tcp-ip 3.06.01 Yes

References