PT-2026-97043 · Lwip · Lwip
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
lwIP versions 2.0.1 through 2.2.1
Description
A double free vulnerability exists in the lwIP API, which occurs when the system attempts to free the same memory location twice. This flaw can lead to system crashes, denial of service, memory corruption, or arbitrary code execution on the victim system. The issue affects critical infrastructure worldwide, including chemical, energy, financial services, healthcare, transportation, and water systems. Real-world incidents have been observed where attackers exploited this flaw to gain initial access to critical infrastructure, using memory corruption to achieve privilege escalation and lateral movement across unencrypted OT (Operational Technology) networks.
Recommendations
Update lwIP versions 2.0.1 through 2.2.1 to a newer version that contains a fix.
Implement runtime segmentation to contain post-compromise activity in industrial environments.
Fix
LPE
DoS
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lwip