Freertos
Vendor:
First CVE: Dec 6, 2018 · Active for 7 years
18
Total CVEs
More Total CVEs than 93% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Freertos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2018
7 years ago
Most Recent CVE
Jun 4, 2025
415 days ago
CVE Severity & Scoring
Freertos18 CVEs
39%
44%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (22.2%)
Network14 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (38.9%)
High11 (61.1%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (16.7%)
High0 (0.0%)
None15 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32020CRITICAL The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory. | May 3, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-31572CRITICAL The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer. | Apr 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-31571CRITICAL The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation. | Apr 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-16601HIGH An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A | Dec 6, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-16526HIGH Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to lea | Dec 6, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-16525HIGH Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to exe | Dec 6, 2018 | 8.1 | 27 | NO | NO |
CVE-2021-43997HIGH FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 d | Nov 17, 2021 | 7.8 | 24 | NO | NO |
CVE-2018-16523HIGH Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow division by zero in prv | Dec 6, 2018 | 7.4 | 24 | NO | NO |
CVE-2025-5688HIGH We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer | Jun 4, 2025 | 7.5 | 23 | NO | NO |
CVE-2024-28115HIGH FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Ori | Mar 7, 2024 | 7.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Freertos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.4.3 | 1 | 7.8 | 0.3% | 0 | 0 |
| 10.4.1 | 1 | 7.8 | 0.3% | 0 | 0 |