CVE-2022-30904

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
01/02/2023
Last modified:
27/03/2025

Description

In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, because there is no check for the SegN field of the Transaction Start PDU.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bestechnic:bluetooth_mesh_software_development_kit:1.0:*:*:*:*:*:*:*
cpe:2.3:h:bestechnic:bes2300:-:*:*:*:*:*:*:*