Micrium develops embedded real-time operating systems and networking libraries for IoT and microcontroller applications, with its vulnerability surface concentrated in UC/HTTP and related middleware components. The observed weakness classes center on memory-safety and pointer-handling issues such as integer overflow and NULL-pointer dereference, typical of C-based embedded codebases exposed to untrusted network input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Micrium over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26706CRITICAL An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functions do not check for integer overflow when allocating a pool | Jan 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-13583HIGH A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker ca | Feb 10, 2021 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Micrium.
Media articles that mention a CVE ID that affects a product developed by Micrium — matched by CVE ID, not by vendor name.