Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2021-26444

Опубликовано: 09 нояб. 2021
Источник: msrc
CVSS3: 3.3
EPSS Низкий

Описание

Azure RTOS Information Disclosure Vulnerability

FAQ

What is RTOS?

Azure RTOS is an embedded development suite including a small but powerful operating system that provides reliable, ultra-fast performance for resource-constrained devices. See Azure RTOS Overview for more information.

What version of Azure RTOS has the update that protects from this vulnerability?

Version 6.1.9

According to the CVSS, User Interaction is Required. What interaction would the user have to do?

Exploitation of this vulnerability requires that a user plug in a malicious USB device.

What is the action required to take the update?

Developers using USBX source code need to recompile their project with the updated source code and retest their HID device application.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 78%
0.01134
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
около 4 лет назад

Azure RTOS Information Disclosure Vulnerability

CVSS3: 3.3
github
больше 3 лет назад

Azure RTOS Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-42301, CVE-2021-42323.

CVSS3: 5.5
fstec
около 4 лет назад

Уязвимость операционных систем Azure RTOS, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 78%
0.01134
Низкий

3.3 Low

CVSS3