CVE-2022-39293 is a critical write buffer overflow vulnerability affecting Azure RTOS USBX, specifically within the eclipse threadx_usbx component. An attacker can exploit an integer overflow in the _ux_host_class_pima_read function by manipulating the header_length value in a device response, leading to an out-of-bounds write. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe impact with high confidentiality, integrity, and availability compromise, and can be exploited remotely without authentication. While no public exploits, Metasploit modules, or significant community discussion have been observed, the vulnerability has been patched in USBX release 6.1.12.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.12CPE matchmatch criteria | cpe:2.3:a:eclipse:threadx_usbx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.