{"id":"CVE-2017-20283","title":"NXP MQX Classic before 5.0 contains an out-of-bounds write vulnerability in the RTCS UDP recvfrom() implementation","summary":"NXP MQX Classic before 5.0 contains an out-of-bounds write vulnerability in the RTCS UDP recvfrom() implementation. Improper enforcement of the application-supplied receive buffer length may allow a crafted UDP packet to overflow the des…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-787"],"vendor":"NXP","product":"MQX","affected":["MQX < 5.0 Classic"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T03:16:32.343","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2017-20283","references":[{"url":"https://community.nxp.com/t5/MQX-Software-Solutions/Horrible-memory-leak-in-recvfrom-that-has-gone-completely/m-p/705993","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T03:03:35.549Z","slug":"CVE-2017-20283","body":"## Overview\n\nNXP MQX Classic before 5.0 contains an out-of-bounds write vulnerability in the RTCS UDP recvfrom() implementation. Improper enforcement of the application-supplied receive buffer length may allow a crafted UDP packet to overflow the destination buffer, resulting in memory corruption, or denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}