FreeRTOS Remote Code Execution Vulnerabilities
Security researchers have disclosed details of thirteen critical vulnerabilities in the FreeRTOS kernel. They claim that a remote attacker could exploit some or all these vulnerabilities to cause a denial-of-service condition, collect information from system memory or execute arbitrary code on affected systems.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Security researchers have disclosed details of thirteen critical vulnerabilities in the FreeRTOS kernel. They claim that a remote attacker could exploit some or all these vulnerabilities to cause a denial-of-service condition, collect information from system memory or execute arbitrary code on affected systems.
Affected platforms
The following platforms are known to be affected:
Threat details
FreeRTOS is a popular open-source real-time operating system used in embedded systems, including internet of things and medical devices. Since 2017, it has been maintained by Amazon (sometimes referred to as a:FreeTROS), after they added a wide range of new modules and capabilities.
All thirteen vulnerabilities are related to FreeRTOS' TCP/IP software stack and the Amazon Web Services secure connectivity module. At the time of publication, the researchers have not released any further details to allow vendors to produce patches.
For further information:
- CVE-2018-16522 - Remote code execution
- CVE-2018-16523 - Denial-of-Service
- CVE-2018-16524 - Information leak
- CVE-2018-16525 - Remote code execution
- CVE-2018-16526 - Remote code execution
- CVE-2018-16527 - Information leak
- CVE-2018-16528 - Remote code execution
- CVE-2018-16598 - Other
- CVE-2018-16599 - Information leak
- CVE-2018-16600 - Information leak
- CVE-2018-16601 - Information leak
- CVE-2018-16602 - Information leak
Remediation advice
Amazon have addressed these vulnerabilities in FreeRTOS 1.3.2. Organisations should apply this update to their affected systems immediately.
Remediation steps
CVE Vulnerabilities
Last edited: 11 January 2022 4:01 pm