CVE-2022-36063 is a critical vulnerability affecting Azure RTOS USBx, specifically within its USB CDC ECM host support. An integer underflow and buffer overflow in the _ux_host_class_cdc_ecm_mac_address_get function can be triggered by manipulating the MAC address string descriptor length. This flaw carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and potential for remote code execution or denial of service. While a fix is available in USBX release 6.1.12, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.11CPE matchmatch criteria | cpe:2.3:a:eclipse:threadx_usbx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.