In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
Metrics
Affected Vendors & Products
References
History
Thu, 18 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use‑After‑Free via DELETE Connection in Eclipse 4diac FORTE Management Interface |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free). | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-06-18T14:40:32.904Z
Reserved: 2026-05-21T07:43:54.846Z
Link: CVE-2026-9158
Updated: 2026-06-18T14:33:38.193Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T19:45:16Z