Use of uninitialized resource in Azure Sphere - #VU47398

 

Use of uninitialized resource in Azure Sphere - #VU47398

Published: October 7, 2020


Vulnerability identifier: #VU47398
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources in the Littlefs filesystem functionality. A local attacker can use a specially crafted set of syscalls, trigger uninitialized usage of resources and gain access to sensitive information on the system.


Affected software

Azure Sphere

Remediation

Install updates from vendor's website.

Azure Sphere - update to 20.07

External References

Related Security Bulletins