CVE-2025-0695
An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
An attacker may cause a Denial-of-Service (DoS) condition on the component embedding the library.
January 31, 2025
This issue affects: Cesanta Frozen below version 1.7.
CVE-2025-0695
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3
Update to Cesanta Frozen version 1.7.
Diego Zaffaroni of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more