← Vulnerability feed

Vulnerability record · CVE-2018-16522 · published 6 December 2018

CVE-2018-16522: Amazon web services freertos vulnerability

Amazon · Amazon Web Services Freertos

Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt.

8.1 CVSS 3.0 High EPSS 2.0% · top 19.6% CWE-824 · CWE-824
8.1CVSS 3.0 base score, v2 6.8
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-16522 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2018-16601Amazon web services freertos vulnerabilityAn issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…EPSS 4.2%8.1CVE-2018-16525Amazon web services freertos vulnerabilityAmazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…EPSS 4.4%8.1CVE-2018-16526Amazon web services freertos vulnerabilityAmazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…EPSS 4.4%8.1CVE-2018-16528Amazon web services freertos improper input validation vulnerabilityAmazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in pr…EPSS 3.3%7.5CVE-2019-13120Amazon web services freertos out-of-bounds read vulnerabilityAmazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory …EPSS 1.2%7.4CVE-2018-16523Amazon web services freertos divide by zero vulnerabilityAmazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…EPSS 2.0%5.9CVE-2018-16602Amazon web services freertos information exposure vulnerabilityAn issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…EPSS 1.8%5.9CVE-2018-16603Amazon web services freertos information exposure vulnerabilityAn issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2018-16522), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.