As cited
Copy frozen at (site build).
vulnerabilities
Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices
Security researchers at runZero discovered seven unpatched vulnerabilities in FatFs, a widely used filesystem driver in industrial equipment and smart devices. The bugs can enable memory corruption and arbitrary code execution through a crafted filesystem image, requiring physical access to the affected device. Developers across multiple industries will need to implement patches as they become available.
Why it matters: These vulnerabilities require physical access but affect pervasive firmware, making device inventory and patching strategies critical for organizations relying on FatFs-based equipment.
- Source published
- First seen by Cybersecurity Tracker