Savannah lwIP SMTP client
Summary
A critical vulnerability (CVE-2026-15340) has been identified in Savannah's lwIP SMTP client versions prior to 2.2.1, where a buffer overflow condition could lead to remote code execution or device crashes. The vulnerability stems from the client failing to check the size of input data. This flaw affects critical infrastructure sectors like energy and water, with a worldwide deployment.
IFF Assessment
This vulnerability allows for remote code execution and device crashes, posing a significant threat to critical infrastructure and impacting defenders.
Severity
The CVSS score of 9.8 (CRITICAL) indicates a severe vulnerability. The vector string (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) highlights that it is network-exploitable with low complexity, no privileges required, no user interaction, and high impacts on confidentiality, integrity, and availability.
Defender Context
This vulnerability represents a critical threat to operational technology (OT) systems, particularly in sectors like energy and water. Defenders should prioritize patching or mitigating this flaw, as it allows for unauthenticated remote code execution which could disrupt essential services. Monitoring for exploitation attempts and ensuring robust network segmentation for OT environments are crucial.