CVE-2018-16528: Amazon Web Services Freertos

High severity, CVSS 8.1. EPSS: 3.3% chance of exploitation in the next 30 days.

Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGD_SecureConnect_Connect in AWS TLS connectivity modules.

Affected products

  • Amazon Amazon Web Services Freertos: up to and including 1.3.1

Published 2018-12-06. Last modified 2026-06-17.