CVE-2023-4424

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
21/11/2023
Last modified:
29/11/2023

Description

An malicious BLE device can cause buffer overflow by sending malformed advertising packet BLE device using Zephyr OS, leading to DoS or potential RCE on the victim BLE device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:* 3.4.0 (including)