CVE-2018-16523 describes a division-by-zero vulnerability in the prvCheckOptions function of Amazon Web Services (AWS) FreeRTOS (through 1.3.1), FreeRTOS (up to V10.0.1 with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. This vulnerability carries a CVSSv3 score of 7.4 (HIGH), indicating a high potential impact on confidentiality and availability, with high attack complexity and no user interaction required. While the vulnerability is publicly known and has received some media coverage, there is no evidence of active exploitation, nor are there readily available public exploits like Metasploit or Nuclei modules. The EPSS score is low, suggesting a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.1CPE matchmatch criteria | cpe:2.3:a:amazon:amazon_web_services_freertos:*:*:*:*:*:*:*:* | ||
<= 10.0.1CPE matchmatch criteria | cpe:2.3:a:amazon:freertos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.