CVE-2022-39343 is a high-severity vulnerability affecting Azure RTOS FileX versions prior to 6.2.0, stemming from integer under/overflows within its Fault Tolerant feature. Specifically, crafted log entries of type FX_FAULT_TOLERANT_DIR_LOG_TYPE can be used to trigger buffer overflows and modify memory contents during the recovery process. This local attack, requiring user interaction, could lead to high impact on confidentiality, integrity, and availability. While no active exploitation, public exploits, or significant community discussion have been observed, a patch is available in version 6.2.0, and a workaround is documented.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.2.0CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_rtos_filex:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.