Weston Embedded maintains a focused set of embedded systems libraries and networking components, including the uC/HTTP, Cesium NET, uC/FTPS, and uC/TCP-IP products that serve resource-constrained IoT and embedded applications. Its vulnerability profile reflects the scope and deployment context of these narrowly scoped, foundational networking and protocol-handling libraries rather than broad consumer or enterprise software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weston Embedded over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27882CRITICAL A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to | Nov 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-31247CRITICAL A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to co | Nov 14, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-45318CRITICAL A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arb | Feb 20, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-28391CRITICAL A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code exe | Nov 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-28379CRITICAL A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code exe | Nov 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-25181CRITICAL A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbit | Nov 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-24585CRITICAL An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. | Nov 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-46378HIGH An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets c | May 10, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-46377HIGH An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets c | May 10, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-41985HIGH An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authe | May 10, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weston Embedded.
Media articles that mention a CVE ID that affects a product developed by Weston Embedded — matched by CVE ID, not by vendor name.