CVE-2025-63929
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-12
Last updated on: 2025-11-13
Assigner: MITRE
Description
Description
A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple threads enqueue elements concurrently via IEC10X_PrioEnQueue, the function may dereference a null or freed queue pointer, resulting in a segmentation fault and potential denial-of-service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| airpig2011 | iec104 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-476 | The product dereferences a pointer that it expects to be valid but is NULL. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a null pointer dereference in the airpig2011 IEC104 software. It occurs when multiple threads try to enqueue elements concurrently using the IEC10X_PrioEnQueue function. The function may attempt to dereference a null or freed queue pointer, which causes a segmentation fault.
How can this vulnerability impact me? :
The impact of this vulnerability is a potential denial-of-service condition due to the segmentation fault caused by dereferencing a null or freed pointer when multiple threads enqueue elements concurrently.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70