Mbed is an embedded operating system and development platform for IoT and constrained devices, with a focused vulnerability profile centered on its core OS product. The durable signal reflects memory-safety and bounds-checking weaknesses, including improper array-index validation, integer overflow, and out-of-bounds writes, which are characteristic of low-level firmware and embedded systems code. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mbed over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17212CRITICAL Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_pa | Nov 5, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-17211CRITICAL An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_packet_data_size_2() is used to calculate the required memory | Nov 5, 2019 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mbed.
Media articles that mention a CVE ID that affects a product developed by Mbed — matched by CVE ID, not by vendor name.