CVE-2019-13120: Amazon Web Services Freertos

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability.

Affected products

  • Amazon Amazon Web Services Freertos: up to and including 1.4.8

Published 2019-10-07. Last modified 2026-06-17.