CVE-2017-14202
The shell implementation does not protect against buffer overruns resulting in unpredictable behavior.
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
29 Aug 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
Affected products
Zephyr · shellWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →