Ethernut is a lightweight embedded operating system designed for microcontroller-based devices, presenting a narrow but specialized attack surface in the embedded systems landscape. Its observed vulnerabilities cluster around memory-access issues such as out-of-bounds reads and writes, along with insufficient randomness in cryptographic contexts, reflecting the low-level nature of kernel and firmware development. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ethernut over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25110CRITICAL An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked, and is used for internal memor | Dec 11, 2020 | 9.8 | 58 | NO | NO |
CVE-2020-25109CRITICAL An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked against the data present. This | Dec 11, 2020 | 9.8 | 58 | NO | NO |
CVE-2020-25108CRITICAL An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked (it can be set to an arbitrary value from a packet). This m | Dec 11, 2020 | 9.8 | 58 | NO | NO |
CVE-2020-25107CRITICAL An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name has '\0' termination. This may lead to successful Denial-of- | Dec 11, 2020 | 9.8 | 58 | NO | NO |
CVE-2020-27213HIGH An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As | Oct 10, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ethernut.
Media articles that mention a CVE ID that affects a product developed by Ethernut — matched by CVE ID, not by vendor name.