CVE-2023-38562: Weston-Embedded Uc-TCP-IP
Critical severity, CVSS 9.1. EPSS: 1.1% chance of exploitation in the next 30 days.
A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.
Affected products
- Weston-Embedded Uc-TCP-IP: version 3.06.01 only
Published 2024-02-20. Last modified 2026-06-17.