CVE detail
CVE-2021-22547 — CVE-2021-22547
Published 2021-05-04 · Modified 2026-06-17 · Vendor google · Product cloud_iot_device_sdk_for_embedded_c · Source nvd
MEDIUM
severity
CVSS-derived band
0.0022
EPSS probability
exploitation probability, 30d
12.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the other parts of the heap. We recommend upgrading the Google Cloud IoT Device SDK for Embedded C used to 1.0.3 or greater.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References