CVE-2021-26444: Azure RTOS Information Disclosure Vulnerability

Overview

Severity
Low (CVSS 3.3)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Nov
Released
2021-11-09
EPSS Score
1.13% (percentile: 78.4%)

FAQ

What is RTOS? Azure RTOS is an embedded development suite including a small but powerful operating system that provides reliable, ultra-fast performance for resource-constrained devices. See Azure RTOS Overview for more information. What version of Azure RTOS has the update that protects from this vulnerability? Version 6.1.9 According to the CVSS, User Interaction is Required. What interaction would the user have to do? Exploitation of this vulnerability requires that a user plug in a malicious USB device. What is the action required to take the update? Developers using USBX source code need to recompile their project with the updated source code and retest their HID device application.

Affected Products (1)

Azure

  • Azure Real Time Operating System

Acknowledgments

Szymon Heidrich

Revision History

  • 2021-11-09: Information published.