CRITICAL🇵🇱 Wersja polska

CVE-2023-48692

CVSS 9.0v3.1pub. 2023-12-05upd. 2024-11-21

Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to icmp, tcp, snmp, dhcp, nat and ftp in RTOS v6.2.1 and below. The fixes have been included in NetX Duo release 6.3.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

🤖 AI Analysis
How it works

The vulnerabilities (CWE-787: out-of-bounds write, CWE-825: expired pointer dereference) occur in components handling network protocols: ICMP, TCP, SNMP, DHCP, NAT, and FTP. An attacker can send specially crafted network packets that cause buffer overflow beyond its boundaries or access to incorrect memory areas. The result is the ability to take control of code execution flow on the target device without any user interaction and without prior authentication.

Impact

An attacker can remotely execute arbitrary code (RCE) on a vulnerable device, which in practice means complete takeover of an embedded system or IoT device, including the ability to compromise confidentiality, integrity, and availability of data and device functions.

Mitigation & patch

Azure RTOS NetX Duo should be updated to version 6.3.0 or later, which includes the fixes. The manufacturer does not indicate any alternative workarounds — updating is the only recommended action.

Who is affected

Azure RTOS NetX Duo version 6.2.1 and earlier — components handling ICMP, TCP, SNMP, DHCP, NAT, and FTP protocols

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Azure Rtos Netx Duo

    OS
    Microsoft
    < 6.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-48316CRITICAL9.8PL ✓same product

RCE przez przepełnienie pamięci w Azure RTOS NetX Duo (SNMP, SMTP, FTP, DTLS)

CVE-2023-48315HIGH8.8same product

Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT appl...

CVE-2023-48691HIGH8.1same product

Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT appl...

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)