Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Write in TLS 1.3 Handshake Message Cache of NetX Duo |
Wed, 07 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it. | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-10-07T08:55:12.097Z
Reserved: 2026-09-30T14:46:53.599Z
Link: CVE-2026-103416
No data.
Status : Received
Published: 2026-10-07T09:17:04.647
Modified: 2026-10-07T09:17:04.647
Link: CVE-2026-103416
No data.
OpenCVE Enrichment
Updated: 2026-10-07T10:30:15Z
